CVE-2018-17057 is a critical deserialization vulnerability in TCPDF versions prior to 6.2.22, specifically affecting products like LimeSurvey that integrate TCPDF. Attackers can exploit this flaw via the phar:// wrapper to trigger deserialization of arbitrary data, potentially leading to remote code execution. With a CVSS score of 9.8 (CRITICAL) and no user interaction required, this vulnerability presents a significant risk for complete compromise of confidentiality, integrity, and availability. While not listed in CISA's KEV catalog, an ExploitDB entry (EDB-46634) confirms active exploitation capabilities for LimeSurvey, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.2.22CPE matchmatch criteria | cpe:2.3:a:tecnick:tcpdf:*:*:*:*:*:*:*:* | ||
< 3.16.0CPE matchmatch criteria | cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.