Description
Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://www.pdfreactor.com/important-pdfreactor-security-advisory/
Release Notes, Vendor Advisory x_refsource_confirm
https://www.pdfreactor.com/pdfreactor-10-maintenance-release-10-1-10722-now-available/
Third Party Advisory x_refsource_misc
https://blog.gdssecurity.com/labs/2019/5/28/ssrf-and-xxe-vulnerabilities-in-pdfreactor.html
Scores
CVSS v3
10.0
EPSS
0.0169
EPSS Percentile
74.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Details
CWE
CWE-918
Status
published
Products (1)
realobjects/pdfreactor
< 10.1.10722
Published
Jun 11, 2019
Tracked Since
Feb 18, 2026