NA

CVE-2024-1648

Published: 20/02/2024 Updated: 20/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

electron-pdf version 20.0.0 allows an external malicious user to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.