wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T09:36:44.415Z
Reserved: 2022-07-11T00:00:00
Link: CVE-2022-35583
No data.
Status : Analyzed
Published: 2022-08-22T16:15:09.473
Modified: 2025-03-18T18:42:23.757
Link: CVE-2022-35583
No data.
OpenCVE Enrichment
No data.