#VU71373 Command Injection in iText - CVE-2021-43113
Published: January 20, 2023
iText
iText Group NV
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper input validation within the GhostscriptHelper.java when processing data passed via a CompareTool filename. A remote attacker can pass a specially crafted file to the application and execute arbitrary Java code on the system.