Blind trust: what is hidden behind the process of creating your PDF file?
swarm.ptsecurity.com | research | #appsec | #vulnerability-research | #web-security | #deserialization | #ssrf | #pdf | #dompdf | #mpdf | #tcpdf
Summary
PT SWARM analyzed seven HTML-to-PDF libraries including TCPDF, mPDF, dompdf and jsPDF, finding 13 vulnerabilities plus risky defaults enabling SSRF, data leaks and DoS, with threat model and PoCs.
- Published
- Collected
Skip to content