Researchers have disclosed an unpatched security vulnerability in “dompdf,” a PHP-based HTML to PDF converter. The flaw allows a malicious party to upload font files with a.php extension to the web server, which can then be activated by using an XSS vulnerability to inject HTML into a web page before it’s rendered as a PDF. The vulnerability was reported to the open-source project maintainers on October 5, 2021, but the developers are yet to provide a timeline by when the fixes are expected to be rolled out.”]
Source: https://thehackernews.com/2022/03/unpatched-rce-bug-in-dompdf-project.html

