CVE-2024-32489: XSS
Published Apr 15, 2024
·Updated
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
Affected Software
2 affected componentsFixes available
composer/tecnickcom/tcpdf<6.7.4
6.7.4
Tcpdf Project Tcpdf<6.7.4
Remediation
Event History
Apr 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
RemedyAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-32489?
The severity of CVE-2024-32489 is classified as medium risk due to HTML syntax mishandling.
2
How do I fix CVE-2024-32489?
To fix CVE-2024-32489, upgrade TCPDF to version 6.7.4 or later.
3
What versions of TCPDF are affected by CVE-2024-32489?
TCPDF versions prior to 6.7.4 are affected by CVE-2024-32489.
4
What type of vulnerability is CVE-2024-32489?
CVE-2024-32489 is a code execution vulnerability due to improper handling of HTML syntax.
5
Is CVE-2024-32489 easy to exploit?
CVE-2024-32489 may be exploited relatively easily, particularly if the affected software processes untrusted HTML input.