icon

We found results for “

CVE-2021-43691

Good to know:

icon

Date: November 29, 2021

tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-22

Top Fix

icon

Upgrade Version

Upgrade to version civicrm/civicrm-packages - 4.5.1;civicrm/civicrm-packages - 4.6.0;febrianrz/crudbooster - v2.1.3;febrianrz/crudbooster - 5.2.x-dev;nahansans/crudbooster - v2.1.6;nahansans/crudbooster - v2.1.3;nahansans/crudbooster - v2.1.14;nahansans/crudbooster - v2.1.10;nahansans/crudbooster - 5.2.x-dev;priana/crudbooster - v2.1.3;priana/crudbooster - 5.2.x-dev;abenzakour/crudbooster - 5.2.x-dev;abenzakour/crudbooster - v2.1.3;cigarrita-worker/cigarrita-api - no_fix;brendomorassi/crudbooster - 5.2.x-dev;brendomorassi/crudbooster - v2.1.3;christopherney/crudbooster - v2.1.3;christopherney/crudbooster - 5.2.x-dev;nimesh143/crudbooster - 5.2.x-dev;nimesh143/crudbooster - v2.1.3;whytobe/crudbooster - 5.2.x-dev;whytobe/crudbooster - v2.1.3;mezhenko/dompdf - no_fix;mezhenko/dompdf - v0.6.0-b3;mezhenko/dompdf - v0.5.2;speedovation/laravelmart - 0.2;speedovation/laravelmart - dev-Laravel5;crocodicstudio/crudbooster - v2.1.3;crocodicstudio/crudbooster - 5.2.x-dev;vanwhebin/dompdf - v0.6.2;narutovn/dompdf - v0.7.0-beta;flamingosrules/dompdf - v0.6.2;chillzy/dompdf - v0.6.2;amr.hosney/dompdf - v0.7.0-beta;odaiatef/crudbooster - v2.1.3;odaiatef/crudbooster - 5.2.x-dev;serdarozturk/dompdf - v0.7.0-beta;serdarozturk/dompdf - v0.6.0-b3;sendaxe/senda-gnre - no_fix;sendaxe/senda-gnre - v1.0.0;intelogie/dompdf - v0.6.0-b3;intelogie/dompdf - v0.7.0-beta;cedricfrancoys/qinoa - v1.0;nakamuraagatha/crudder - v2.1.3;nakamuraagatha/crudder - 5.2.x-dev;dkapusta/dompdf - v0.7.0-beta;tomsmile/crudbooster - 5.2.x-dev;tomsmile/crudbooster - v2.1.3;thewulf00/dompdf - v0.6.0-b3;thewulf00/dompdf - v0.7.0-beta;hoffmann-andras/dompdf - v0.7.0-beta;hoffmann-andras/dompdf - v0.6.0-b3;coldtrick/event_manager - v5.0;coldtrick/event_manager - no_fix;traitify/client - dev-untested;chocri/nxdompdf - v0.7.0-beta;dompdf/dompdf - v0.7.0-beta;dompdf/dompdf - v0.6.0-b3;santhoshjanan/crudbooster - v2.1.3;santhoshjanan/crudbooster - 5.2.x-dev;digsolab/dompdf - v0.6.0-b3;digsolab/dompdf - v0.6.1-dsl;ashwinrana/crudbooster - v2.1.3;ashwinrana/crudbooster - 5.2.x-dev;psh24053/crudbooster - 5.2.x-dev;psh24053/crudbooster - v2.1.3;coldtrick/pages_tools - no_fix;coldtrick/pages_tools - dev-dependabot/composer/dompdf/dompdf-1.2.1;brunodebarros/dompdf - v0.7.0-beta;brunodebarros/dompdf - v0.6.0-b3;sfneal/dompdf - v0.7.0-beta;xzy/dompdf - v0.7.0-beta;tekintian/dompdf - v0.7.0-beta;sandeshsays/crudbooster - v2.1.3;micdavino/crudbooster - v2.1.3;mramadan0101/dompdf - v0.7.0-beta;blacksmurf/symfony2-core-bundle - no_fix;saptarshimondal/crudbooster - 5.2.x-dev;saptarshimondal/crudbooster - v2.1.3;versatecnologia/dompdf - v0.7.0-beta;zaxx44a/crudbooster - v2.1.11;zaxx44a/crudbooster - v2.1.3;zaxx44a/crudbooster - 5.2.x-dev;trafficfox/dompdf - v0.7.0-beta;bizprove/dompdf - v0.7.0-beta;bvbmedia/multishop - no_fix;tango/tango - v1.x-dev;myhayo/dompdf - v0.7.0-beta;lucien-correia/one-signal - no_fix;lucien-correia/one-signal - dev-master;monkeytie/dompdf - v0.6.0-b3;monkeytie/dompdf - dev-0.6.2-hotfix;monkeytie/dompdf - v0.7.0-beta;pleio/event_manager - v0.4;kgcoder/ar-dompdf - v0.6.2;baklysystems/dompdf - v0.6.2;strangetin/dompdf - v0.7.0-beta;bueno-networks/dompdf - v0.6.2;bellcom/os2subsites - no_fix;aha/dompdf - v0.7.0-beta

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): HIGH

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): LOW
Authentication (AU): NONE
Confidentiality (C): PARTIAL
Integrity (I): PARTIAL
Availability (A): PARTIAL
Additional information:

Do you need more information?

Contact Us