Description
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
Problem types
Product status
Credits
Musyoka Ian
References
www.exploit-db.com/exploits/50995 (ExploitDB-50995)
mpdf.github.io/ (Official mPDF Project Homepage)
www.vulncheck.com/advisories/mpdf-local-file-inclusion (VulnCheck Advisory: mPDF 7.0 - Local File Inclusion)