CVE-2024-22640
HIGHTCPDF <=6.6.5 - Regular Expression Denial of Service via Crafted HTML Color
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-22640. PoCs published by zunak.
AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2024-22640, demonstrating a ReDoS vulnerability in TCPDF <= 6.7.4. The PoC exploits a crafted HTML color string to trigger excessive backtracking in a regular expression, leading to a denial of service.
Description
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
Exploits (1)
This repository contains a functional proof-of-concept for CVE-2024-22640, demonstrating a ReDoS vulnerability in TCPDF <= 6.7.4. The PoC exploits a crafted HTML color string to trigger excessive backtracking in a regular expression, leading to a denial of service.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H