Описание
Cross-site Scripting in Pyhtml2pdf
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Пакеты
Наименование
pyhtml2pdf
pip
Затронутые версииВерсия исправления
<= 0.0.6
Отсутствует
Связанные уязвимости
CVSS3: 7.5
nvd
почти 2 года назад
Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.