CVE-2023-28458

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/04/2023
Last modified:
05/02/2025

Description

pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an arbitrary file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pretalx:pretalx:*:*:*:*:*:*:*:* 2.3.1 (including)