Dismissed
Permalink
CVE-2022-50897
6.2 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @jopejoe1 ignored package termpdfpy
- @LeSuisse dismissed
mPDF 7.0 - Local File Inclusion
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
References
-
ExploitDB-50995 exploit
-
Official mPDF Project Homepage product
-
VulnCheck Advisory: mPDF 7.0 - Local File Inclusion third-party-advisory
Affected products
mPDF
- ==7.0
Ignored packages (1)
pkgs.termpdfpy
A graphical pdf (and epub, cbz, ...) reader that works inside the kitty terminal.
-
nixos-unstable 2022-03-28
- nixpkgs-unstable 2022-03-28
- nixos-unstable-small 2022-03-28