PT-2022-18977 · Dompdf · Dompdf

CVE-2022-28368

·

Published

2022-04-03

·

Updated

2023-08-08

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dompdf versions prior to 1.2.1
Description The issue allows remote code execution via a .php file in the src field of an @font-face Cascading Style Sheets (CSS) statement within an HTML input file. This is a general information about the issue, and no specific details about the number of potentially affected devices or real-world incidents are provided.
Recommendations For Dompdf versions prior to 1.2.1, update to version 1.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the @font-face CSS statement or validating user input to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-28368
GHSA-X752-QJV4-C4HC

Affected Products

Dompdf