2025.1.0
7 years ago
1 months ago
Known vulnerabilities in the pretalx package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
pretalx is a Conference organisation: CfPs, scheduling, much more Affected versions of this package are vulnerable to Directory Traversal in HTML export (a non-default feature). Users are able to upload crafted HTML documents that trigger the reading of arbitrary files. How to fix Directory Traversal? Upgrade | [,2.3.2) |
pretalx is a Conference organisation: CfPs, scheduling, much more Affected versions of this package are vulnerable to Directory Traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an arbitrary file. How to fix Directory Traversal? Upgrade | [,2.3.2) |