Headline
GHSA-wh3w-jcc7-mhmf: pretalx vulnerable to path traversal in HTML export
pretalx before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.
pretalx vulnerable to path traversal in HTML export
Moderate severity GitHub Reviewed Published Apr 20, 2023 to the GitHub Advisory Database • Updated Apr 24, 2023
Related news
CVE-2023-28459: Fix path traversal in static HTML export · pretalx/pretalx@60722c4
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.