CVE-2022-28368

CRITICAL9.8EPSS 88.3%

Remote code injection in dompdf/dompdf

Published: 4/4/2022Modified: 2/16/2024
Also known as:GHSA-x752-qjv4-c4hc

Description

Dompdf is an HTML to PDF converter. Dompdf before 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (11)