Information Disclosure Vulnerability in Dompdf by Dominik Homberger
CVE-2014-5011

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 January 2020

What is CVE-2014-5011?

The Dompdf library, widely used for converting HTML to PDF files, contains a vulnerability that allows for unauthorized information disclosure. Versions prior to 0.6.2 are susceptible to this flaw, which may enable attackers to access sensitive data through crafted requests. It is critical for users of Dompdf to update to version 0.6.2 or later to mitigate this risk and protect their applications from inadvertent data exposure.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-5011 : Information Disclosure Vulnerability in Dompdf by Dominik Homberger