Dompdf allows remote file inclusion because URI validation failure does not halt font registration
High severity
GitHub Reviewed
Published
Sep 26, 2022
to the GitHub Advisory Database
•
Updated Feb 5, 2024
Description
Published by the National Vulnerability Database
Sep 25, 2022
Published to the GitHub Advisory Database
Sep 26, 2022
Reviewed
Sep 30, 2022
Last updated
Feb 5, 2024
registerFont
inFontMetrics.php
in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a@font-face
rule.References