CRITICAL🇵🇱 Wersja polska

CVE-2023-23924

CVSS 10.0v3.1pub. 2023-02-01upd. 2024-11-21

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:H
  • Dompdf Project Dompdf

    APP
    Dompdf Project
    2.0.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2021-3902CRITICAL9.8PL ✓same product

XXE w parserze SVG biblioteki dompdf umożliwia SSRF i PHAR deserialization

CVE-2021-3838CRITICAL9.8PL ✓same product

RCE przez PHAR deserialization w DomPDF przed wersją 2.0.0

CVE-2023-24813CRITICAL10.0PL ✓same product

Dompdf: bypass ochrony URL przez rozbieżność parsera atrybutów SVG

CVE-2022-28368CRITICAL9.8PL ✓same product

Dompdf 1.2.1 — RCE przez plik .php w dyrektywie @font-face CSS

CVE-2022-41343HIGH7.5same product

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation f...