Description
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
Remediation
References
Related Vulnerabilities
PHP mail function ASCII control character header spoofing vulnerability
WordPress Plugin Comment Rating 'id' Parameter SQL Injection (2.9.23)
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2020-1967)
WordPress Plugin Social Share Icons & Social Share Buttons Unspecified Vulnerability (1.4)