Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://pypi.org/project/pyhtml2pdf/ | product |
https://fluidattacks.com/advisories/oliver/ | third party advisory exploit |