← Back

CVE-2019-12153

nvd nist
Published: Jun 11, 2019Modified: Nov 21, 2024

JSON object

Loading...
10.0
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.8
Source: NVD

Description

Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content.

Affected (1)

1 product
Pdfreactor
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.1.10722

References (6)

Timeline

No history available yet.