CVE-2024-51058: Medium severity composer/tecnickcom/tcpdf vulnerability
Published Nov 26, 2024
·Updated
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.
Affected Software
2 affected componentsFixes available
composer/tecnickcom/tcpdf<=6.7.5
6.7.6
Tcpdf Project Tcpdf=6.7.5
Remediation
Event History
Nov 26, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyAffected Software
Advisory Published
via GitHub·06:38 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-51058?
CVE-2024-51058 is considered a high-severity Local File Inclusion (LFI) vulnerability affecting TCPDF 6.7.5.
2
How do I fix CVE-2024-51058?
To fix CVE-2024-51058, update TCPDF to version 6.7.6 or later.
3
What can be exploited in CVE-2024-51058?
CVE-2024-51058 can be exploited to read arbitrary files from the server's file system, potentially exposing sensitive information.
4
Is my software affected by CVE-2024-51058?
If you are using TCPDF version 6.7.5, your software is affected by CVE-2024-51058.
5
How does CVE-2024-51058 work?
CVE-2024-51058 works by allowing file paths to be controlled through the <img> src tag, leading to unintended file disclosures.