pretalx before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files.
{
"github_reviewed_at": "2023-04-24T20:16:25Z",
"github_reviewed": true,
"severity": "HIGH",
"nvd_published_at": "2023-04-20T21:15:08Z",
"cwe_ids": [
"CWE-22"
]
}