CVE-2023-28115 is a critical PHAR deserialization vulnerability affecting Snappy, a PHP library for generating thumbnails, snapshots, or PDFs. The flaw, present in versions prior to 1.4.2, allows an attacker to achieve remote code execution by uploading arbitrary files and leveraging the `phar://` protocol within the `file_exists()` function, especially when Snappy is integrated with frameworks possessing known POP chains. This vulnerability carries a CVSS score of 9.8 (Critical) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Successful exploitation can lead to complete system compromise. Currently, there is no evidence of active exploitation, and no public exploit code or Metasploit/Nuclei modules are available. Community discussion and media coverage for this CVE are minimal, which is typical for a significant percentage of vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.4.2CPE matchmatch criteria | cpe:2.3:a:knplabs:snappy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.