• caglararli@hotmail.com
  • 05386281520

CVE-2024-25117 | dompdf php-svg-lib up to 0.5.1 parseCssStyle file inclusion

Çağlar Arlı      -    70 Views

CVE-2024-25117 | dompdf php-svg-lib up to 0.5.1 parseCssStyle file inclusion

A vulnerability was found in dompdf php-svg-lib up to 0.5.1 and classified as problematic. This issue affects the function Style::fromAttributes/Style::parseCssStyle. The manipulation leads to file inclusion. The identification of this vulnerability is CVE-2024-25117. Local access is required to approach this attack. There is no exploit available. It is recommended to upgrade the affected component.