CVE-2022-35583
critical · 9.8wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
9.8
CVSS
15.4%
EPSS (exploit prob.)
97th
EPSS percentile
2022-08-22
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-918
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wkhtmltopdf | wkhtmltopdf | 0.12.6 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/171446/wkhtmltopdf-0.12.6-Server-Side-Request-Forgery.html
- https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently
- https://drive.google.com/file/d/1LAmf_6CJLk5qDp0an2s_gVQ0TN2wmht5/view?usp=sharing
- https://wkhtmltopdf.org/
- http://packetstormsecurity.com/files/171446/wkhtmltopdf-0.12.6-Server-Side-Request-Forgery.html
- https://cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silently
- https://drive.google.com/file/d/1LAmf_6CJLk5qDp0an2s_gVQ0TN2wmht5/view?usp=sharing
- https://wkhtmltopdf.org/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2022-35583