An issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker to execute arbitrary operating system commands on the local server.
| Software | From | Fixed in |
|---|---|---|
| apryse / html2pdf | 11.5.0 | 11.5.0.x |
| apryse / html2pdf | 11.7.0 | 11.7.0.x |
| apryse / html2pdf | 11.10.0 | 11.10.0.x |