CVE-2022-50897
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
13/01/2026
Last modified:
13/01/2026
Description
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
6.20
Severity 3.x
MEDIUM



