A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
{
"cpe": "cpe:2.3:a:sensepost:gowitness:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.3.6"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}