CVE-2024-56527

HIGH

TCPDF < 6.8.0 - Cross-Site Scripting via Error Function

Title source: llm
STIX 2.1

Description

An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message.

Scores

CVSS v3 7.5
EPSS 0.0070
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
tcpdf_project/tcpdf < 6.8.0
tecnickcom/tcpdf 0 - 6.8.0Packagist
Published Dec 27, 2024
Tracked Since Feb 18, 2026