Lucene search

K
prionPRIOn knowledge basePRION:CVE-2019-19450
HistorySep 20, 2023 - 2:15 p.m.

Remote code execution

2023-09-2014:15:00
PRIOn knowledge base
www.prio-n.com
6
reportlab
paraparser
remote code execution
xml document
python code
cve-2019-17626
nvd

9.6 High

AI Score

Confidence

High

0.051 Low

EPSS

Percentile

93.0%

paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in a unichar element in a crafted XML document with ‘<unichar code="’ followed by arbitrary Python code, a similar issue to CVE-2019-17626.

CPENameOperatorVersion
debian_linuxeq10.0
reportlablt3.5.31