CVE-2018-17057

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
Configurations

Configuration 1

cpe:2.3:a:tecnick:tcpdf:*:*:*:*:*:*:*:*
cpe:2.3:a:limesurvey:limesurvey:*:*:*:*:*:*:*:*

Information

Published : 2018-09-14 08:29

Updated : 2019-04-26 04:38


NVD link : CVE-2018-17057

Mitre link : CVE-2018-17057

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data