ZeroHour

CVE-2024-1647

PoC
CVSS 3.1
7.5 high
EPSS
<1%p51
Published
()
Modified
Description

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.

Vendors
kumaf
Products
pyhtml2pdf
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.