logo

Database

Insecure deserialization In tecnickcom/tcpdf

Description

TCPDF vulnerable to attackers triggering deserialization of arbitrary data An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions