Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-02-19T23:59:17.082Z

Updated: 2024-08-23T19:34:38.896Z

Reserved: 2024-02-19T21:52:22.394Z

Link: CVE-2024-1647

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.662Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-20T01:15:07.717

Modified: 2024-11-21T08:50:59.913

Link: CVE-2024-1647

cve-icon Redhat

No data.