Skip to main content

Files or Directories Accessible to External Parties

CVE-2024-51058

Severity Medium
Score 6.9/10

Summary

Local File Inclusion (LFI) vulnerability has been discovered in TCPDF. This vulnerability enables a user to read arbitrary files from the server's file system through "<img>" src tag, potentially exposing sensitive information. This issue affects tecnickcom/tcpdf versions prior to 6.7.6.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-552 - Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

Advisory Timeline

  • Published