← Back

CVE-2024-1647

nvd nist
Published: Feb 20, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: help@fluidattacks.com (Secondary)

Description

Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.

Affected (1)

Products: Kumaf: Pyhtml2pdf
1 product
Pyhtml2pdf
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.0.6

References (4)

Source: help@fluidattacks.com
ExploitThird Party Advisory
Source: help@fluidattacks.com
Product
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Product

Timeline

No history available yet.