PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include
local files from the server and display them in the generated PDF.
This issue was fixed in PDF Export Module version 0.7.6.
Metrics
Affected Vendors & Products
References
History
Fri, 15 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sanitization. An unauthenticated user could craft the html payload which could include local files from the server and display them in the generated PDF. This issue was fixed in PDF Export Module version 0.7.6. | |
| Title | Path Traversal in PDF Export Module | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-05-15T13:14:32.252Z
Reserved: 2026-04-21T12:09:57.293Z
Link: CVE-2026-41552
Updated: 2026-05-15T13:14:28.642Z
Status : Awaiting Analysis
Published: 2026-05-15T13:16:18.990
Modified: 2026-05-15T14:12:43.710
Link: CVE-2026-41552
No data.
OpenCVE Enrichment
Updated: 2026-05-15T14:45:16Z