CVE-2019-17626

CVE-2019-17626

ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document with ‘<span color="’ followed by arbitrary Python code.

Source: CVE-2019-17626

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다