Lucene search

K
cvelistMitreCVELIST:CVE-2019-19450
HistorySep 20, 2023 - 12:00 a.m.

CVE-2019-19450

2023-09-2000:00:00
mitre
www.cve.org
2
cve-2019-19450
reportlab
code execution
paraparser
xml document
python

9.9 High

AI Score

Confidence

High

0.051 Low

EPSS

Percentile

93.0%

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with ‘<unichar code="’ followed by arbitrary Python code, a similar issue to CVE-2019-17626.