CVE-2019-12153

CRITICAL

RealObjects PDFreactor <10.1.10722 - SSRF

Title source: llm
STIX 2.1

Description

Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.

References (3)

Core 3

Scores

CVSS v3 10.0
EPSS 0.0169
EPSS Percentile 74.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-918
Status published
Products (1)
realobjects/pdfreactor < 10.1.10722
Published Jun 11, 2019
Tracked Since Feb 18, 2026