Fiche vulnérabilité
CVE-2022-35583 : faille critique wkhtmltopdf wkhtmltopdf (CVSS 9.8)
Description
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
En bref
- Sévérité
- Critique (CVSS 9.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 22 août 2022
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- wkhtmltopdf wkhtmltopdf