Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Blind trust: what is hidden behind the process of creating your PDF file?

Summary

PT SWARM analyzed seven HTML-to-PDF libraries including TCPDF, mPDF, dompdf and jsPDF, finding 13 vulnerabilities plus risky defaults enabling SSRF, data leaks and DoS, with threat model and PoCs.
Published
Collected

original ↗

Related coverage

back