CVE-2021-3838 describes a critical PHAR deserialization vulnerability in DomPDF versions prior to 2.0.0. This flaw allows an attacker to achieve remote code execution by uploading a malicious file and leveraging the phar:// protocol within file_get_contents(), leading to the instantiation of arbitrary PHP objects. With a CVSS score of 9.8 (Critical), this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the potential for severe consequences, especially when integrated with frameworks like Laravel, warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:dompdf_project:dompdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.