Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain

arbitrary local files. This is possible because the application does not

validate the HTML content entered by the user.



Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 12 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Kumaf
Kumaf pyhtml2pdf
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:kumaf:pyhtml2pdf:0.0.6:*:*:*:*:*:*:*
Vendors & Products Kumaf
Kumaf pyhtml2pdf

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published:

Updated: 2024-08-23T19:34:38.896Z

Reserved: 2024-02-19T21:52:22.394Z

Link: CVE-2024-1647

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.662Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-20T01:15:07.717

Modified: 2025-02-12T17:03:00.353

Link: CVE-2024-1647

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.