CVE-2023-39062
MEDIUMhtml2pdf < 5.2.8 - Cross-Site Scripting via forms.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-39062. PoCs published by afine-com.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2023-39062, an XSS vulnerability in Spipu Html2Pdf's example files. It includes proof-of-concept HTTP requests demonstrating the vulnerability in `forms.php` and `example9.php` due to insufficient input sanitization.
Description
Cross Site Scripting vulnerability in Spipu HTML2PDF before v.5.2.8 allows a remote attacker to execute arbitrary code via a crafted script to the forms.php.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2023-39062, an XSS vulnerability in Spipu Html2Pdf's example files. It includes proof-of-concept HTTP requests demonstrating the vulnerability in `forms.php` and `example9.php` due to insufficient input sanitization.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N