CVE-2018-19047
mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.
- Affected products
- Mpdf
- Mpdf Project Mpdf
- ≤ 7.1.6
- Fix
- Available
- CVSS 3.0
- 10.0 CRITICAL
- EPSS
- 2.1% (80th percentile)
- Weakness
- CWE-918
- NVD status
- Modified
- Published
- 2018-11-07
CVE-2018-19047 at NVD
No indexed exploits for CVE-2018-19047 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2018-19047 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.