{"id":"PYSEC-2023-40","details":"pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an arbitrary file.","aliases":["CVE-2023-28458","GHSA-23fx-92m6-4f2g"],"modified":"2026-06-10T17:01:44.279579461Z","published":"2023-04-20T21:15:00Z","references":[{"type":"FIX","url":"https://github.com/pretalx/pretalx/commit/60722c43cf975f319e94102e6bff320723776890"},{"type":"ARTICLE","url":"https://www.sonarsource.com/blog/pretalx-vulnerabilities-how-to-get-accepted-at-every-conference/"},{"type":"WEB","url":"https://github.com/pretalx/pretalx/releases/tag/v2.3.2"},{"type":"WEB","url":"https://pretalx.com/p/news/security-release-232/"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-23fx-92m6-4f2g"}],"affected":[{"package":{"name":"pretalx","ecosystem":"PyPI","purl":"pkg:pypi/pretalx"},"ranges":[{"type":"GIT","repo":"https://github.com/pretalx/pretalx","events":[{"introduced":"0"},{"fixed":"60722c43cf975f319e94102e6bff320723776890"}]},{"type":"ECOSYSTEM","events":[{"introduced":"2.3.1"},{"fixed":"2.3.2"}]}],"versions":["2.3.1","v2.3.1","v2.3.0","v2.2.0","v2.1.1","v2.1.0","v2.0.0","v1.1.0","v1.0.0","v0.9.0","v0.8.0","v0.7.1","v0.7.0","v0.6.1","v0.6.0","v0.5.0","v0.4.1","v0.4.0","v0.3.1","v0.3.0","v0.2.2","v0.2.1","v0.2.0","v0.1.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/pretalx/PYSEC-2023-40.yaml"}}],"schema_version":"1.7.5"}