VDB
Sign up
HIGH8.8

GHSA-6m93-343m-3jrc

Cross-site Scripting in HTML2PDF

Quick fix

GHSA-6m93-343m-3jrc — spipu/html2pdf: upgrade to the fixed version with the command below.

composer require spipu/html2pdf:^5.2.4

Details

An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the injection of a malicious <link> tag in the converted HTML document.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/spipu/html2pdf
Introduced in: 0Fixed in: 5.2.4
Fixcomposer require spipu/html2pdf:^5.2.4

References