CVE-2023-33733

HIGH

Reportlab <3.6.12 - RCE

Title source: llm

Description

Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.

Exploits (5)

nomisec WORKING POC 120 stars
by c53elyas · poc
https://github.com/c53elyas/CVE-2023-33733
nomisec WORKING POC 2 stars
by L41KAA · poc
https://github.com/L41KAA/CVE-2023-33733-Exploit-PoC
nomisec WORKING POC 1 stars
by onion2203 · poc
https://github.com/onion2203/Lab_Reportlab
nomisec WORKING POC 1 stars
by buiduchoang24 · poc
https://github.com/buiduchoang24/CVE-2023-33733
nomisec WRITEUP
by hoangbui24 · poc
https://github.com/hoangbui24/CVE-2023-33733

Scores

CVSS v3 7.8
EPSS 0.2461
EPSS Percentile 96.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
pypi/reportlab 0 - 3.6.13PyPI
reportlab/reportlab < 3.6.12
Published Jun 05, 2023
Tracked Since Feb 18, 2026