VDB
Sign up
MEDIUM6.2

GHSA-rmv2-8jjc-23xw

TCPDF Local File Inclusion vulnerability

Quick fix

GHSA-rmv2-8jjc-23xw — tecnickcom/tcpdf: upgrade to the fixed version with the command below.

composer require tecnickcom/tcpdf:^6.7.6

Details

Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/tecnickcom/tcpdf
Introduced in: 0Fixed in: 6.7.6
Fixcomposer require tecnickcom/tcpdf:^6.7.6

References