cve/2022/CVE-2022-41343.md

24 lines
928 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-41343](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41343)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
### POC
#### Reference
- https://tantosec.com/blog/cve-2022-41343/
2024-06-09 00:33:16 +00:00
- https://tantosec.com/blog/cve-2022-41343/
2024-05-25 21:48:12 +02:00
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Amodio/h5p_quiz
- https://github.com/BKreisel/CVE-2022-41343
- https://github.com/BKreisel/CVE-2022-46169
- https://github.com/fardeen-ahmed/Bug-bounty-Writeups
- https://github.com/nomi-sec/PoC-in-GitHub