CVE-2023-28459

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/04/2023
Last modified:
05/02/2025

Description

pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pretalx:pretalx:*:*:*:*:*:*:*:* 2.3.1 (including)