VulnerabilityModified
CVE-2022-28368
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
CRITICAL 9.8EPSS 82.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 82.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 82.44% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- dompdf project/dompdf
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/171738/Dompdf-1.2.1-Remote-Code-Execution.html
- https://github.com/dompdf/dompdf/commit/4c70e1025bcd9b7694b95dd552499bd83cd6141dPatch, Third Party Advisory
- https://github.com/dompdf/dompdf/issues/2598Patch, Third Party Advisory
- https://github.com/dompdf/dompdf/pull/2808Patch, Third Party Advisory
- https://github.com/snyk-labs/php-goofThird Party Advisory
- https://packagist.org/packages/dompdf/dompdf#v1.2.1Product, Third Party Advisory
- https://snyk.io/blog/security-alert-php-pdf-library-dompdf-rce/Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/171738/Dompdf-1.2.1-Remote-Code-Execution.html
- https://github.com/dompdf/dompdf/commit/4c70e1025bcd9b7694b95dd552499bd83cd6141dPatch, Third Party Advisory
- https://github.com/dompdf/dompdf/issues/2598Patch, Third Party Advisory
- https://github.com/dompdf/dompdf/pull/2808Patch, Third Party Advisory
- https://github.com/snyk-labs/php-goofThird Party Advisory
- https://packagist.org/packages/dompdf/dompdf#v1.2.1Product, Third Party Advisory
- https://snyk.io/blog/security-alert-php-pdf-library-dompdf-rce/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.