vendor:
mpdf
by:
ZadYree
7.5
CVSS
HIGH
File Disclosure
22
CWE
Product Name: mpdf
Affected Version From: 5.3 and prior
Affected Version To: 5.3 and prior
Patch Exists: NO
Related CWE: N/A
CPE: a:mpdf:mpdf
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Multiple
2011
mPDF <= 5.3 File Disclosure Exploit (0day)
This vulnerability, due to a weak filter, lets you download any unprotected remote content, under PDF format. The exploit may not work, depending on the set up htaccess/chmod rules on the remote server.
Mitigation:
Ensure that the filter is properly configured to prevent unauthorized access to files.