First published: Tue Jan 18 2022(Updated: )
An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Chm2pdf | <5.2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45394 is considered a critical vulnerability due to the potential for remote code execution through deserialization of arbitrary data.
To fix CVE-2021-45394, upgrade Spipu HTML2PDF to version 5.2.4 or later.
Attackers can exploit CVE-2021-45394 to inject malicious <link> tags that can trigger deserialization of arbitrary data.
CVE-2021-45394 affects all versions of HTML2PDF prior to 5.2.4.
You can determine if your system is vulnerable by checking if you are using a version of HTML2PDF older than 5.2.4.