Source |
The Hacker News |
Identifiant |
4292026 |
Date de publication |
2022-03-16 06:14:32 (vue: 2022-03-16 14:05:56) |
Titre |
Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters |
Texte |
Researchers have disclosed an unpatched security vulnerability in "dompdf," a PHP-based HTML to PDF converter, that, if successfully exploited, could lead to remote code execution in certain configurations.
"By injecting CSS into the data processed by dompdf, it can be tricked into storing a malicious font with a .php file extension in its font cache, which can later be executed by accessing it |
Notes |
|
Envoyé |
Oui |
Condensat |
accessing affects based bug cache can certain code configurations converter converters could css data disclosed dompdf executed execution exploited extension file font have html injecting its later lead malicious pdf php processed project rce remote researchers security storing successfully tricked unpatched vulnerability which |
Tags |
Vulnerability
Guideline
|
Stories |
|
Move |
|