CVE-2022-35583

CRITICAL

Wkhtmltopdf - SSRF

Title source: rule

Description

wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.

Exploits (1)

exploitdb WORKING POC
by Momen Eldawakhly · textwebappsasp
https://www.exploit-db.com/exploits/51039

Scores

CVSS v3 9.8
EPSS 0.5942
EPSS Percentile 98.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-918
Status published
Products (1)
wkhtmltopdf/wkhtmltopdf 0.12.6
Published Aug 22, 2022
Tracked Since Feb 18, 2026