CVE-2023-28458 is a path traversal vulnerability affecting pretalx versions 2.3.1 and earlier, specifically within its non-default HTML export feature. An authenticated organizer can exploit this to overwrite arbitrary files on the server with the pretalx 404 page content. While rated Medium (CVSS 4.3) for its low impact (data integrity loss), its FAUCET Risk Score of 98/100 and high EPSS score suggest a significant potential for exploitation. A Metasploit module exists, demonstrating a path from limited file write to remote code execution, though there is no evidence of active exploitation or widespread community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.3.1CPE matchmatch criteria | cpe:2.3:a:pretalx:pretalx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.