CVE-2022-28368: Code Injection
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
Other sources
Dompdf is an HTML to PDF converter. Dompdf before 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-28368?
CVE-2022-28368 is a vulnerability that allows remote code execution in Dompdf before version 1.2.1 via a .php file in the src:url field of an @font-face CSS statement within an HTML input file.
How severe is CVE-2022-28368?
CVE-2022-28368 has a severity rating of 9.8 out of 10, which is considered critical.
What software is affected by CVE-2022-28368?
Dompdf before version 1.2.1 is affected by CVE-2022-28368.
How can I fix CVE-2022-28368?
To fix CVE-2022-28368, upgrade Dompdf to version 1.2.1 or higher.
Where can I find more information about CVE-2022-28368?
You can find more information about CVE-2022-28368 on the following references: [GitHub Advisory](https://github.com/advisories/GHSA-x752-qjv4-c4hc), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-28368), and [Dompdf GitHub issue](https://github.com/dompdf/dompdf/issues/2598).