Description
Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound HTTP requests by passing user-controlled URLs to the addMediaFromUrl() method in InteractsWithMedia.php.
Problem types
Server-Side Request Forgery (SSRF)
Product status
Any version before 11.23.0
Credits
Xurshidbek Sobirjonov
VulnCheck
References
github.com/spatie/laravel-medialibrary/releases/tag/11.23.0
github.com/spatie/laravel-medialibrary/pull/3939
github.com/...ommit/608ea03703d3887c46434f5dda6af56de6346aba
www.vulncheck.com/...-media-library-ssrf-via-addmediafromurl