Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34939
HistoryApr 04, 2022 - 7:50 a.m.

Remote Code Execution (RCE)

2022-04-0407:50:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

0.161 Low

EPSS

Percentile

96.0%

Dompdf is vulnerable to remote code execution. The vulnerability exists due to a lack of sanitization of the font type via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

CPENameOperatorVersion
dompdf/dompdflev1.2.0
dompdf/dompdflev1.2.0