Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3cwc-m7c2-qr86

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

mPDF Unsafe Deserialization

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

Пакеты

Наименование

mpdf/mpdf

composer
Затронутые версииВерсия исправления

<= 7.1.7

7.1.8

EPSS

Процентиль: 54%
0.00318
Низкий

8.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
около 7 лет назад

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

EPSS

Процентиль: 54%
0.00318
Низкий

8.8 High

CVSS3

Дефекты

CWE-502