CVE-2022-50897
EUVD-2026-263813.01.2026, 23:15
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| mpdf_project | mpdf | 7.0.0 |
𝑥
= Vulnerable software versions