CVE-2022-41343
25.09.2022, 19:15
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.Enginsight
| Vendor | Product | Version |
|---|---|---|
| dompdf_project | dompdf | 𝑥 < 2.0.1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References