CVE-2022-28368
CRITICALDompdf 1.2.1 - RCE
Title source: llmDescription
Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
Exploits (5)
exploitdb
WORKING POC
by Ravindu Wickramasinghe · pythonwebappsphp
https://www.exploit-db.com/exploits/51270
github
WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/dompdf v1.2.1 RCE (CVE-2022-28368)
nomisec
WORKING POC
by Henryisnotavailable · poc
https://github.com/Henryisnotavailable/Dompdf-Exploit-RCE
nomisec
WORKING POC
by That-Guy-Steve · poc
https://github.com/That-Guy-Steve/CVE-2022-28368-handler
References (7)
Scores
CVSS v3
9.8
EPSS
0.7041
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-79
Status
published
Products (2)
dompdf/dompdf
0 - 1.2.1Packagist
dompdf_project/dompdf
< 1.2.1
Published
Apr 03, 2022
Tracked Since
Feb 18, 2026