CVE-2024-1648
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: help@fluidattacks.com (Secondary)
Description
electron-pdf version 20.0.0 allows an external attacker to remotely obtain
arbitrary local files. This is possible because the application does not
validate the HTML content entered by the user.
Affected (1)
Products: Fraserxu: Electron Pdf
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 20.0.0 |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.