CVE-2024-47617: Controller Mediastreamcontroller Php Cwe 79 Cve 2024 47617
The `downloadAction` method does not accept or validate a `$slug` parameter representing the requested filename. This allows attackers to manipulate the URL's file extension (e.g., adding `.html`), leading to Cross-Site Scripting (XSS) via MIME-sniffing.
Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0PHPβ
greprules fetch cve-2024-47617-controller-mediastreamcontroller-php-cwe-79-cve-2024-47617 --engine opengrepDescription
The `downloadAction` method does not accept or validate a `$slug` parameter representing the requested filename. This allows attackers to manipulate the URL's file extension (e.g., adding `.html`), leading to Cross-Site Scripting (XSS) via MIME-sniffing.
Community feedback
0 signals from signed-in users.
- Useful
- 0
- False positive
- 0
- Metadata
- 0