snyk-labs/php-goof

snyk-labs/php-goof

Releases0
Stars26
Snyk PHP Goof - A vulnerable PHP demo application

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL7.5 HIGH

Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).