CVE-2023-33733 is a code-injection vulnerability in ReportLab through version 3.6.12. An attacker can supply a crafted PDF file to trigger arbitrary code execution. The specific vulnerable function and the fixed ReportLab release are not available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a Python 3 exploit script (exp.py) for CVE-2023-33733, a vulnerability in a web application (likely ReportHub or a similar product). The exploit allows an attacker to execute arbitrary system commands on the target server by abusing a vulnerable endpoint. The script requires the attacker to supply the target host, port, command to execute, and a valid session cookie or credentials. It first authenticates (if credentials are provided) to obtain a session cookie, then crafts a malicious multipart/form-data POST request to the /leaveRequest endpoint, injecting the attacker's command. The README provides detailed usage instructions, including how to use the script to obtain a reverse shell. The main code file is exp.py, which handles argument parsing, authentication, payload construction, and sending the exploit request. The attack vector is network-based, targeting HTTP endpoints. No hardcoded IPs or domains are present; the script is designed to be used against arbitrary targets specified by the user.
This repository demonstrates a proof-of-concept (PoC) exploit for a code injection vulnerability in the Reportlab Python library (version 3.6.12). The vulnerability allows an attacker to achieve remote code execution (RCE) by injecting malicious Python code into the color attribute of HTML tags processed by Reportlab. The exploit leverages a bypass of the library's sandboxing mechanism, allowing access to dangerous Python built-ins and ultimately enabling arbitrary command execution. The repository contains three files: - README.md: A detailed write-up explaining the vulnerability, the sandbox bypass, and exploitation steps. - code-injection-poc/poc.py: The main PoC script, which crafts a malicious HTML paragraph with an injected payload. When processed by Reportlab, this payload executes a system command to create the file '/tmp/exploited', demonstrating successful exploitation. - code-injection-poc/requirements.txt: Specifies the vulnerable Reportlab version (3.6.12). The exploit targets applications that use Reportlab to generate PDFs from user-supplied HTML. The attack vector is typically network-based, as the attacker submits crafted HTML input to a vulnerable web application. The main fingerprintable endpoint is the file '/tmp/exploited', which serves as evidence of code execution. The exploit is a PoC and does not include a weaponized or easily customizable payload, but it clearly demonstrates the risk and impact of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-impact locally exploitable vulnerability affecting Unity Linux / UOS Server packages, requiring user interaction according to the supplied CVSS v3 vector and potentially compromising confidentiality, integrity, and availability.
A Splunk vulnerability in which a lower-privileged user can push notifications containing potentially malicious code to all users, enabling privilege abuse or escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.