← Back to CVE List

CVE-2018-19047

Published: 2018-11-07T05:29Z
Last Modified: 2024-11-21T03:57Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt