漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Vulnerability Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an <image> element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
通过错误消息导致的信息暴露
Vulnerability Title
dompdf 信息泄露漏洞
Vulnerability Description
dompdf是dompdf团队开源的一个 HTML 到 PDF 的转换器。 dompdf 3.1.6之前版本存在信息泄露漏洞,该漏洞源于SVG渲染功能对文件访问处理不当,可能导致恶意攻击者利用data-URI编码的SVG文档泄露文件系统信息。
CVSS Information
N/A
Vulnerability Type
N/A