CVE-2023-28459
MEDIUMpretalx < 2.3.2 - Path Traversal via HTML Export Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-28459.
PoCs published by Stefan Schiller, msutovsky-r7, including Metasploit module auxiliary/scanner/http/pretalx_file_read_cve_2023_28459.
AI-analyzed exploit summary This Metasploit module exploits CVE-2023-28459 in Pretalx, allowing arbitrary file read via a crafted proposal submission that references a file path in an HTML tag. The exploit leverages the schedule export functionality to retrieve the file contents in a ZIP archive.
Description
pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.
Exploits (1)
This Metasploit module exploits CVE-2023-28459 in Pretalx, allowing arbitrary file read via a crafted proposal submission that references a file path in an HTML tag. The exploit leverages the schedule export functionality to retrieve the file contents in a ZIP archive.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N