URI validation failure on SVG parsing. Bypass of CVE-2023-23924
CVE-2023-24813

10CRITICAL

Key Information:

Vendor

DomPDF

Status
Vendor
CVE Published:
7 February 2023

What is CVE-2023-24813?

A vulnerability in Dompdf allows attackers to exploit the differences in attribute parsing between Dompdf and php-svg-lib. By manipulating the 'image' tag's href attribute and providing an SVG file with deliberately crafted parameters, an attacker can bypass security protections. This exploitation can lead to arbitrary unserialize, which poses risks such as arbitrary file deletion and may enable remote code execution. It is essential for users to upgrade to version 2.0.3 or later, as no effective workarounds exist.

Affected Version(s)

dompdf = 2.0.2

References

EPSS Score

5% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-24813 : URI validation failure on SVG parsing. Bypass of CVE-2023-23924