Unpatched RCE Bug in dompdf Project Affects HTML to PDF Converters

Discussion in 'News Aggregator' started by Ravie Lakshmanan, 16 Mar 2022.

  1. Researchers have disclosed an unpatched security vulnerability in "dompdf," a PHP-based HTML to PDF converter, that, if successfully exploited, could lead to remote code execution in certain configurations. "By injecting CSS into the data processed by dompdf, it can be tricked into storing a malicious font with a .php file extension in its font cache, which can later be executed by accessing it

    Continue reading...
     

Share This Page

Loading...