CVE-2023-23924

Public Exploit
URI validation failure on SVG parsing in Dompdf

Description

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can be bypassed on SVG parsing by passing `<image>` tags with uppercase letters. This may lead to arbitrary object unserialize on PHP < 8, through the `phar` URL wrapper. An attacker can exploit the vulnerability to call arbitrary URL with arbitrary protocols, if they can provide a SVG file to dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize, that will lead to the very least to an arbitrary file deletion and even remote code execution, depending on classes that are available.

Categories

10.0
CVSS
Severity: Critical
CVSS 3.1 •
EPSS 54.78% Top 5%
Third-Party Advisory github.com Third-Party Advisory github.com Third-Party Advisory github.com
Affected: dompdf dompdf
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2023-23924?
CVE-2023-23924 has been scored as a critical severity vulnerability.
How to fix CVE-2023-23924?
To fix CVE-2023-23924, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2023-23924 being actively exploited in the wild?
It is possible that CVE-2023-23924 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~55% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2023-23924?
CVE-2023-23924 affects dompdf dompdf.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.