TCPDF vulnerable to attackers triggering deserialization of arbitrary data
Critical severity
GitHub Reviewed
Published
Oct 6, 2022
to the GitHub Advisory Database
•
Updated Feb 5, 2024
Description
Published to the GitHub Advisory Database
Oct 6, 2022
Reviewed
Oct 6, 2022
Last updated
Feb 5, 2024
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the
phar://
wrapper.References