local files from the server and display them in the generated PDF.
This issue was fixed in PDF Export Module version 0.7.6.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 15 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6. | |
| Title | Path Traversal in PDF Export Module | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-15T13:14:32.252Z
Reserved: 2026-04-21T12:09:57.293Z
Link: CVE-2026-41552
Updated: 2026-05-15T13:14:28.642Z
Status : Awaiting Analysis
Published: 2026-05-15T13:16:18.990
Modified: 2026-05-15T14:12:43.710
Link: CVE-2026-41552
No data.
OpenCVE Enrichment
Updated: 2026-05-15T14:45:16Z