CVE-2023-23924: Critical-Severity RCE Flaw Found in Popular Dompdf Library
A high-severity security flaw has been disclosed in the open-source Dompdf PHP library that, if successfully exploited, could lead to remote code execution on a target server.
版权声明:admin 发表于 2023年2月3日 上午8:55。
转载请注明:CVE-2023-23924: Critical-Severity RCE Flaw Found in Popular Dompdf Library | CTF导航
转载请注明:CVE-2023-23924: Critical-Severity RCE Flaw Found in Popular Dompdf Library | CTF导航
相关文章
暂无评论...
“An attacker might be able to exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will leads at the very least to an arbitrary file deletion, and might leads to remote code execution, depending on classes that are available,” developer Bsweeney wrote in the advisories.