WeasyPrint 帮助 Web 开发人员生成 PDF 文档。在 70.0 之前,如果服务器端应用配置了一个限制性的 ,并将受攻击者影响的值传入 ,攻击者可以通过 或 选项绕过该限制。 具体而言,在 中, 调用 时未使用文档的 ,这使得可访问的本地文件可以被读取并原样嵌入到输出的 PDF 中。在 中, 构造 时也未使用文档的 ,从而允许加载本地或内部资源,并且这种宽松的限制会被嵌套的 CSS 和 引用所传播。其中, 通道会应用已获取的资源,但本身并不会将样式表中的注释原样披露出来。 该问题已在 70.0 版本中修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Kozea | WeasyPrint | < 70.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet