Critical severity9.8NVD Advisory· Published Aug 22, 2022· Updated Jun 17, 2026
CVE-2022-35583
CVE-2022-35583
Description
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- wkhtmlTOpdf/wkhtmlTOpdfdescription
- Range: 0.12.6
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/171446/wkhtmltopdf-0.12.6-Server-Side-Request-Forgery.htmlnvdExploit
- drive.google.com/file/d/1LAmf_6CJLk5qDp0an2s_gVQ0TN2wmht5/viewnvdExploitThird Party Advisory
- wkhtmltopdf.orgnvdProductVendor Advisory
- cyber-guy.gitbook.io/cyber-guys-blog/blogs/initial-access-via-pdf-file-silentlynvdURL Repurposed
News mentions
0No linked articles in our index yet.