Dompdf 1.2.1 allows remote code execution via a .php file in the src:url field of an @font-face Cascading Style Sheets (CSS) statement (within an HTML input file).
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| dompdf/dompdf(Packagist) | 0 | 1.2.1 | N/A |
CVSS Metrics