PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6.
The vulnerability results from insufficient sanitization of HTML data passed to the PDF export module. An attacker can craft a malicious HTML payload containing references to local server system files. The module processes such payload without path validation, resulting in the inclusion of the contents of the specified files in the generated PDF. The attack requires no authentication.
An attacker can read arbitrary files accessible to the server process, including potentially configuration files, keys, credentials, or other sensitive system resources. This results in high data confidentiality impact in both the local system context and related systems.
The PDF Export Module should be updated to version 0.7.6 or later, in which the vendor has patched vulnerabilities related to file reading. Details are available in the vendor documentation: https://docs.dhtmlx.com/gantt/guides/pdf-export-module-whatsnew/
PDF Export Module in versions below 0.7.6, used in DHTMLX Gantt and DHTMLX Scheduler products
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XDhtmlx Pdf Export Module
APPDhtmlx0.3.3 – 0.7.6 (excl.)
Related vulnerabilities
RCE i command injection w PDF Export Module DHTMLX (Gantt/Scheduler)
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive i...
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive ...
Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) pl...