Description
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
Published: 2022-08-22
Score: 9.8 Critical
EPSS: 58.6% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.4789}

epss

{'score': 0.4848}


Subscriptions

Wkhtmltopdf Wkhtmltopdf
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T09:36:44.415Z

Reserved: 2022-07-11T00:00:00.000Z

Link: CVE-2022-35583

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-08-22T16:15:09.473

Modified: 2025-03-18T18:42:23.757

Link: CVE-2022-35583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses