ZeroHour

CVE-2022-35583

PoC ×2
CVSS 3.1
9.8 critical
EPSS
15%p97
Published
()
Modified
Description

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

Vendors
wkhtmltopdf
Products
wkhtmltopdf
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.