CVE-2022-41343

7.5HIGH

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

Veröffentlicht: 9/25/2022Aktualisiert: 5/22/2025

Beschreibung

registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.

KI-AnalyseKI-gestützt

Betroffene Produkte

dompdf_projectdompdf

Referenzen