Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Path Traversal in PDF Export Module
Vulnerability Description
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6.
CVSS Information
N/A
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
DHTMLX Gantt 路径遍历漏洞
Vulnerability Description
DHTMLX Gantt是DHTMLX公司的一款支持项目计划、任务调度与时间线可视化的JavaScript甘特图组件。 DHTMLX Gantt 0.7.6之前版本存在路径遍历漏洞,该漏洞源于缺乏HTML清理,可能导致未经身份验证的用户构造包含服务器本地文件的HTML有效载荷并在生成的PDF中显示。
CVSS Information
N/A
Vulnerability Type
N/A