CVE-2024-32489Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Project Tcpdf

Severity
6.1MEDIUMNVD
EPSS
0.2%
top 57.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15

Description

TCPDF before 6.7.4 mishandles calls that use HTML syntax.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages3 packages

Packagisttecnickcom/tcpdf< 6.7.4
NVDtcpdf_project/tcpdf< 6.7.4
Debiantcpdf_project/tcpdf< 6.3.5+dfsg1-1+deb11u1+3

Patches

🔴Vulnerability Details

4
OSV
CVE-2024-32489: TCPDF before 62024-04-15
CVEList
CVE-2024-32489: TCPDF before 62024-04-15
GHSA
TCPDF Cross-site Scripting vulnerability2024-04-15
OSV
TCPDF Cross-site Scripting vulnerability2024-04-15

📋Vendor Advisories

1
Debian
CVE-2024-32489: tcpdf - TCPDF before 6.7.4 mishandles calls that use HTML syntax.2024
CVE-2024-32489 — Tcpdf Project Tcpdf vulnerability | cvebase