CVE-2022-28368

CRITICAL

Dompdf 1.2.1 - RCE

Title source: llm

Description

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).

Exploits (5)

exploitdb WORKING POC
by Ravindu Wickramasinghe · pythonwebappsphp
https://www.exploit-db.com/exploits/51270
nomisec WORKING POC 16 stars
by rvizx · poc
https://github.com/rvizx/CVE-2022-28368
github WORKING POC
by dugisan3rd · pythonpoc
https://github.com/dugisan3rd/exploit/tree/main/dompdf v1.2.1 RCE (CVE-2022-28368)
nomisec WORKING POC
by Henryisnotavailable · poc
https://github.com/Henryisnotavailable/Dompdf-Exploit-RCE
nomisec WORKING POC
by That-Guy-Steve · poc
https://github.com/That-Guy-Steve/CVE-2022-28368-handler

Scores

CVSS v3 9.8
EPSS 0.7041
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (2)
dompdf/dompdf 0 - 1.2.1Packagist
dompdf_project/dompdf < 1.2.1
Published Apr 03, 2022
Tracked Since Feb 18, 2026