CVE-2024-56519
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-56519 is a newly disclosed vulnerability in TCPDF, a popular open-source library used for generating PDF files. The issue lies in the function 'setSVGStyles' which fails to sanitize the SVG font-family attribute. An attacker can exploit this flaw to inject malicious code into PDF documents, potentially leading to arbitrary code execution or information disclosure. This vulnerability poses a significant risk to organizations that use TCPDF to generate PDFs, particularly those handling sensitive data. It is recommended that users upgrade to TCPDF version 6.8.0 or later to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.