Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9c5-x9r9-f4w3

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 6.2

Описание

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

EPSS

Процентиль: 7%
0.00026
Низкий

8.7 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-98

Связанные уязвимости

CVSS3: 5.5
nvd
26 дней назад

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

EPSS

Процентиль: 7%
0.00026
Низкий

8.7 High

CVSS4

6.2 Medium

CVSS3

Дефекты

CWE-98