id: PYSEC-2023-41 details: pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files. affected: - package: name: pretalx ecosystem: PyPI purl: pkg:pypi/pretalx ranges: - type: GIT repo: https://github.com/pretalx/pretalx events: - introduced: "0" - fixed: 60722c43cf975f319e94102e6bff320723776890 - type: ECOSYSTEM events: - introduced: 2.3.1 - fixed: 2.3.2 versions: - 2.3.1 references: - type: FIX url: https://github.com/pretalx/pretalx/commit/60722c43cf975f319e94102e6bff320723776890 - type: ARTICLE url: https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/ - type: WEB url: https://github.com/pretalx/pretalx/releases/tag/v2.3.2 - type: WEB url: https://pretalx.com/p/news/security-release-232/ - type: ADVISORY url: https://github.com/advisories/GHSA-wh3w-jcc7-mhmf aliases: - CVE-2023-28459 - GHSA-wh3w-jcc7-mhmf modified: "2023-05-04T03:49:47.257209Z" published: "2023-04-20T21:15:00Z"