CVE-2024-1647
CVSS V2 None
CVSS V3 None
Description
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Overview
- CVE ID
- CVE-2024-1647
- Assigner
- Fluid Attacks
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-02-19T23:59:17.082Z
- Last Modified Date
- 2024-02-19T23:59:17.082Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://pypi.org/project/pyhtml2pdf/ | |
https://fluidattacks.com/advisories/oliver/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-1647 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-1647 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 05:47:14 | Added to TrackCVE |