CVE-2019-12153
Summary
| CVE | CVE-2019-12153 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-11 21:29:00 UTC |
| Updated | 2019-06-17 13:49:00 UTC |
| Description | Lack of validation in the HTML parser in RealObjects PDFreactor before 10.1.10722 leads to SSRF, allowing attackers to access network or file resources on behalf of the server by supplying malicious HTML content. |
Risk And Classification
Problem Types: CWE-918
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Realobjects | Pdfreactor | All | All | All | All |
| Application | Realobjects | Pdfreactor | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PDFreactor 10 Maintenance Release 10.1.10722 now available - Important Security Update - PDFreactor | CONFIRM | www.pdfreactor.com | Release Notes, Vendor Advisory |
| GDS - Blog - SSRF and XXE Vulnerabilities in PDFreactor | MISC | blog.gdssecurity.com | Third Party Advisory |
| Important PDFreactor Security Advisory - PDFreactor | CONFIRM | www.pdfreactor.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.