CRITICAL

CVE-2023-23924

CVSS v3

9.8

CRITICAL

EPSS Score

51.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.

Technical details

Published
2/1/2023

Frequently asked questions

What is CVE-2023-23924?

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.

Is CVE-2023-23924 actively exploited?

Active exploitation of CVE-2023-23924 has not been confirmed. The EPSS score is 51.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-23924?

CVE-2023-23924 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-23924 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.