PT-2018-13869 · Tcpdf · Tcpdf

Q3Rv0

·

Published

2018-09-14

·

Updated

2022-10-06

·

CVE-2018-17057

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TCPDF versions prior to 6.2.22
Description An issue allows attackers to trigger deserialization of arbitrary data via the phar:// wrapper.
Recommendations For versions prior to 6.2.22, update to version 6.2.22 or later to resolve the issue.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2018-17057
GHSA-5HW4-M7F3-HHX8

Affected Products

Tcpdf