Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19047

Опубликовано: 07 нояб. 2018
Источник: nvd
CVSS3: 10
CVSS2: 7.5
EPSS Низкий

Описание

mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mpdf_project:mpdf:*:*:*:*:*:*:*:*
Версия до 7.1.6 (включая)

EPSS

Процентиль: 57%
0.00349
Низкий

10 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 10
github
больше 3 лет назад

** DISPUTED ** mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble."

EPSS

Процентиль: 57%
0.00349
Низкий

10 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-918