CVE-2019-19450
—CVSS 3.1
9.8 critical
EPSS
4%p91
Published
()
Modified
Description
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with '<unichar code="' followed by arbitrary Python code, a similar issue to CVE-2019-17626.
In the news0 stories
No ingested article mentions this CVE yet.