← back
CVE-2022-35583

CVE-2022-35583

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 12%
from disclosure to weapon213 days
Published on NVDAug 22
1st PoC+213d
exploitation probability
12%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.