Skip to content
Noroxi

reportlab records

4 published records for vendor reportlab.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 21
  3. 23

Bar: total · dark part: CISA KEV.

Attack profile

All records

4 records
  • ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document

    CriticalCVSS 9.8No exploitEPSS 10%

    reportlab · reportlabOct 16, 2019

  • paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in

    CriticalCVSS 9.8No exploitEPSS 6%

    reportlab · reportlabSep 20, 2023

  • Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.

    HighCVSS 7.8Proof of conceptEPSS 2%

    reportlab · reportlabJun 5, 2023

  • Server-side Request Forgery (SSRF)

    MediumCVSS 6.5No exploitEPSS 1%

    reportlab · reportlabFeb 18, 2021