Untriaged
mPDF 7.0 - Local File Inclusion
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
Affected products
mPDF
- ==7.0
Matching in nixpkgs
pkgs.termpdfpy
A graphical pdf (and epub, cbz, ...) reader that works inside the kitty terminal.
-
nixos-unstable 2022-03-28
- nixpkgs-unstable 2022-03-28
- nixos-unstable-small 2022-03-28
-
nixos-25.11 2022-03-28
- nixpkgs-25.11-darwin 2022-03-28
-
nixos-25.05 -
- nixos-25.05-small 2022-03-28
Package maintainers
-
@teto Matthieu Coudron <mcoudron@hotmail.com>