Files or Directories Accessible to External Parties
CVE-2024-51058
Summary
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF. This vulnerability enables a user to read arbitrary files from the server's file system through "<img>" src tag, potentially exposing sensitive information. This issue affects tecnickcom/tcpdf versions prior to 6.7.6.
- LOW
- LOCAL
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-552 - Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.
References
Advisory Timeline
- Published