We found results for “”
CVE-2021-43691
Good to know:
Date: November 29, 2021
tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The variable src is coming from $_SERVER["argv"] then there is a path manipulation vulnerability.
Language: PHP
Severity Score
Severity Score
Weakness Type (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22Top Fix
Upgrade Version
Upgrade to version civicrm/civicrm-packages - 4.5.1;civicrm/civicrm-packages - 4.6.0;febrianrz/crudbooster - v2.1.3;febrianrz/crudbooster - 5.2.x-dev;nahansans/crudbooster - v2.1.6;nahansans/crudbooster - v2.1.3;nahansans/crudbooster - v2.1.14;nahansans/crudbooster - v2.1.10;nahansans/crudbooster - 5.2.x-dev;priana/crudbooster - v2.1.3;priana/crudbooster - 5.2.x-dev;abenzakour/crudbooster - 5.2.x-dev;abenzakour/crudbooster - v2.1.3;cigarrita-worker/cigarrita-api - no_fix;brendomorassi/crudbooster - 5.2.x-dev;brendomorassi/crudbooster - v2.1.3;christopherney/crudbooster - v2.1.3;christopherney/crudbooster - 5.2.x-dev;nimesh143/crudbooster - 5.2.x-dev;nimesh143/crudbooster - v2.1.3;whytobe/crudbooster - 5.2.x-dev;whytobe/crudbooster - v2.1.3;mezhenko/dompdf - no_fix;mezhenko/dompdf - v0.6.0-b3;mezhenko/dompdf - v0.5.2;speedovation/laravelmart - 0.2;speedovation/laravelmart - dev-Laravel5;crocodicstudio/crudbooster - v2.1.3;crocodicstudio/crudbooster - 5.2.x-dev;vanwhebin/dompdf - v0.6.2;narutovn/dompdf - v0.7.0-beta;flamingosrules/dompdf - v0.6.2;chillzy/dompdf - v0.6.2;amr.hosney/dompdf - v0.7.0-beta;odaiatef/crudbooster - v2.1.3;odaiatef/crudbooster - 5.2.x-dev;serdarozturk/dompdf - v0.7.0-beta;serdarozturk/dompdf - v0.6.0-b3;sendaxe/senda-gnre - no_fix;sendaxe/senda-gnre - v1.0.0;intelogie/dompdf - v0.6.0-b3;intelogie/dompdf - v0.7.0-beta;cedricfrancoys/qinoa - v1.0;nakamuraagatha/crudder - v2.1.3;nakamuraagatha/crudder - 5.2.x-dev;dkapusta/dompdf - v0.7.0-beta;tomsmile/crudbooster - 5.2.x-dev;tomsmile/crudbooster - v2.1.3;thewulf00/dompdf - v0.6.0-b3;thewulf00/dompdf - v0.7.0-beta;hoffmann-andras/dompdf - v0.7.0-beta;hoffmann-andras/dompdf - v0.6.0-b3;coldtrick/event_manager - v5.0;coldtrick/event_manager - no_fix;traitify/client - dev-untested;chocri/nxdompdf - v0.7.0-beta;dompdf/dompdf - v0.7.0-beta;dompdf/dompdf - v0.6.0-b3;santhoshjanan/crudbooster - v2.1.3;santhoshjanan/crudbooster - 5.2.x-dev;digsolab/dompdf - v0.6.0-b3;digsolab/dompdf - v0.6.1-dsl;ashwinrana/crudbooster - v2.1.3;ashwinrana/crudbooster - 5.2.x-dev;psh24053/crudbooster - 5.2.x-dev;psh24053/crudbooster - v2.1.3;coldtrick/pages_tools - no_fix;coldtrick/pages_tools - dev-dependabot/composer/dompdf/dompdf-1.2.1;brunodebarros/dompdf - v0.7.0-beta;brunodebarros/dompdf - v0.6.0-b3;sfneal/dompdf - v0.7.0-beta;xzy/dompdf - v0.7.0-beta;tekintian/dompdf - v0.7.0-beta;sandeshsays/crudbooster - v2.1.3;micdavino/crudbooster - v2.1.3;mramadan0101/dompdf - v0.7.0-beta;blacksmurf/symfony2-core-bundle - no_fix;saptarshimondal/crudbooster - 5.2.x-dev;saptarshimondal/crudbooster - v2.1.3;versatecnologia/dompdf - v0.7.0-beta;zaxx44a/crudbooster - v2.1.11;zaxx44a/crudbooster - v2.1.3;zaxx44a/crudbooster - 5.2.x-dev;trafficfox/dompdf - v0.7.0-beta;bizprove/dompdf - v0.7.0-beta;bvbmedia/multishop - no_fix;tango/tango - v1.x-dev;myhayo/dompdf - v0.7.0-beta;lucien-correia/one-signal - no_fix;lucien-correia/one-signal - dev-master;monkeytie/dompdf - v0.6.0-b3;monkeytie/dompdf - dev-0.6.2-hotfix;monkeytie/dompdf - v0.7.0-beta;pleio/event_manager - v0.4;kgcoder/ar-dompdf - v0.6.2;baklysystems/dompdf - v0.6.2;strangetin/dompdf - v0.7.0-beta;bueno-networks/dompdf - v0.6.2;bellcom/os2subsites - no_fix;aha/dompdf - v0.7.0-beta
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
CVSS v2
| Base Score: |
|
|---|---|
| Access Vector (AV): | NETWORK |
| Access Complexity (AC): | LOW |
| Authentication (AU): | NONE |
| Confidentiality (C): | PARTIAL |
| Integrity (I): | PARTIAL |
| Availability (A): | PARTIAL |
| Additional information: |
Vulnerabilities
Projects
Contact Us


