Логотип exploitDog
bind:CVE-2019-1000005
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-1000005

Количество 2

Количество 2

nvd логотип

CVE-2019-1000005

около 7 лет назад

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3cwc-m7c2-qr86

больше 3 лет назад

mPDF Unsafe Deserialization

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-1000005

mPDF version 7.1.7 and earlier contains a CWE-502: Deserialization of Untrusted Data vulnerability in getImage() method of Image/ImageProcessor class that can result in Arbitry code execution, file write, etc.. This attack appears to be exploitable via attacker must host crafted image on victim server and trigger generation of pdf file with content <img src="phar://path/to/crafted/image">. This vulnerability appears to have been fixed in 7.1.8.

CVSS3: 8.8
0%
Низкий
около 7 лет назад
github логотип
GHSA-3cwc-m7c2-qr86

mPDF Unsafe Deserialization

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу