Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
History

Wed, 03 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Pyhtml2pdf Project
Pyhtml2pdf Project pyhtml2pdf
CPEs cpe:2.3:a:pyhtml2pdf_project:pyhtml2pdf:*:*:*:*:*:*:*:*
Vendors & Products Pyhtml2pdf Project
Pyhtml2pdf Project pyhtml2pdf
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user. Pyhtml2pdf version 0.0.6 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
First Time appeared Pyhtml2pdf
Pyhtml2pdf pyhtml2pdf
CPEs cpe:2.3:a:pyhtml2pdf:pyhtml2pdf:0.0.6:*:*:*:*:*:*:*
Vendors & Products Pyhtml2pdf
Pyhtml2pdf pyhtml2pdf

Wed, 12 Feb 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Kumaf
Kumaf pyhtml2pdf
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:kumaf:pyhtml2pdf:0.0.6:*:*:*:*:*:*:*
Vendors & Products Kumaf
Kumaf pyhtml2pdf

cve-icon MITRE

Status: PUBLISHED

Assigner: Fluid Attacks

Published: 2024-02-19T23:59:17.082Z

Updated: 2025-12-03T20:21:55.600Z

Reserved: 2024-02-19T21:52:22.394Z

Link: CVE-2024-1647

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.662Z

cve-icon NVD

Status : Modified

Published: 2024-02-20T01:15:07.717

Modified: 2025-12-03T21:15:51.913

Link: CVE-2024-1647

cve-icon Redhat

No data.