CVE-2023-24813 is a critical vulnerability affecting Dompdf, an HTML to PDF converter, stemming from a parsing discrepancy between Dompdf and php-svg-lib. An attacker can craft a malicious SVG file to bypass Dompdf's URL validation, enabling arbitrary URL calls with arbitrary protocols. This can lead to arbitrary unserialization in PHP versions before 8.0.0, potentially resulting in arbitrary file deletion or remote code execution. With a CVSS score of 9.8 (Critical), the vulnerability is easily exploitable over the network with low complexity and no user interaction, impacting confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, users are strongly advised to upgrade to Dompdf version 2.0.3 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0.2CPE matchmatch criteria | cpe:2.3:a:dompdf_project:dompdf:2.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.