CVE-2024-56519: XSS
Published Dec 27, 2024
·Updated
An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute.
Affected Software
2 affected componentsFixes available
composer/tecnickcom/tcpdf<6.8.0
6.8.0
Tcpdf Project Tcpdf<6.8.0
Remediation
Patch Available
Event History
Dec 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-56519?
CVE-2024-56519 is considered a high severity vulnerability due to improper sanitization of the SVG font-family attribute.
2
How do I fix CVE-2024-56519?
To fix CVE-2024-56519, you should upgrade TCPDF to version 6.8.0 or later.
3
What software is affected by CVE-2024-56519?
CVE-2024-56519 affects TCPDF versions prior to 6.8.0.
4
What functionality is impacted by CVE-2024-56519?
CVE-2024-56519 impacts the setSVGStyles function by not properly sanitizing SVG font-family attributes.
5
Are there any known exploits for CVE-2024-56519?
As of now, there are no specific known exploits for CVE-2024-56519, but it is advisable to address the vulnerability promptly.