Description
Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.
Published: 2023-01-31
Score: 10 Critical
EPSS: 51.5% High
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-3cw5-7cxw-v5qg Dompdf vulnerable to URI validation failure on SVG parsing
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.54785}

epss

{'score': 0.57103}


Mon, 10 Mar 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Dompdf Project Dompdf
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-10T21:17:31.944Z

Reserved: 2023-01-19T21:12:31.358Z

Link: CVE-2023-23924

cve-icon Vulnrichment

Updated: 2024-08-02T10:42:27.102Z

cve-icon NVD

Status : Modified

Published: 2023-02-01T00:15:10.693

Modified: 2024-11-21T07:47:06.630

Link: CVE-2023-23924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses