CVE & CISA-KEV Catalog

CVE-2023-24813

CRITICALEPSS 83th pctl
10.0
CVSS v3
NVD

Description

Dompdf is an HTML to PDF converter written in php. Due to the difference in the attribute parser of Dompdf and php-svg-lib, an attacker can still call arbitrary URLs with arbitrary protocols. Dompdf parses the href attribute of `image` tags and respects `xlink:href` even if `href` is specified. However, php-svg-lib, which is later used to parse the svg file, parses the href attribute. Since `href` is respected if both `xlink:href` and `href` is specified, it's possible to bypass the protection on the Dompdf side by providing an empty `xlink:href` attribute. An attacker can exploit the vulnerability to call arbitrary URLs with arbitrary protocols if they provide an SVG file to the Dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, which will lead, at the very least, to arbitrary file deletion and might lead to remote code execution, depending on available classes. This vulnerability has been addressed in commit `95009ea98` which has been included in release version 2.0.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

How to fix

Remediation Available
php-dompdfDebian
Fixed in:2.0.3+dfsg-1CVE-2023-24813
Fixed in:2.0.3+dfsg-1CVE-2023-24813

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploit Intelligence

2.49%probability of exploitation in 30 days
83rdpercentile

Elevated risk: more likely to be exploited than 83% of all known CVEs.

References

Exploit1
Embed a live status badge for CVE-2023-24813
CVE-2023-24813 severity badge

Markdown

[![CVE-2023-24813](https://tridentstack.com/cve/badge/CVE-2023-24813.svg)](https://tridentstack.com/cve/CVE-2023-24813)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-24813"><img src="https://tridentstack.com/cve/badge/CVE-2023-24813.svg" alt="CVE-2023-24813"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.