id: PYSEC-2023-40 details: pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an arbitrary file. affected: - package: name: pretalx ecosystem: PyPI purl: pkg:pypi/pretalx ranges: - type: GIT repo: https://github.com/pretalx/pretalx events: - introduced: "0" - fixed: 60722c43cf975f319e94102e6bff320723776890 - type: ECOSYSTEM events: - introduced: 2.3.1 - fixed: 2.3.2 versions: - 2.3.1 references: - type: FIX url: https://github.com/pretalx/pretalx/commit/60722c43cf975f319e94102e6bff320723776890 - type: ARTICLE url: https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/ - type: WEB url: https://github.com/pretalx/pretalx/releases/tag/v2.3.2 - type: WEB url: https://pretalx.com/p/news/security-release-232/ - type: ADVISORY url: https://github.com/advisories/GHSA-23fx-92m6-4f2g aliases: - CVE-2023-28458 - GHSA-23fx-92m6-4f2g modified: "2023-05-04T03:49:47.207450Z" published: "2023-04-20T21:15:00Z"