Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
wkhtmltopdf 代码问题漏洞
Vulnerability Description
wkhtmltopdf是wkhtmltopdf开源的一个库。用于将 HTML 转换为 PDF。 wkhtmltopdf 0.12.6版本存在代码问题漏洞,该漏洞源于其允许攻击者通过在目标源上注入带有初始资产IP地址的iframe标签来获得对目标系统的初始访问权。这可能导致攻击者通过访问其内部资产来接管整个基础设施。
CVSS Information
N/A
Vulnerability Type
N/A