
This project aims at re-analyzing and PoC about CVE-2023-33733. Reportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.
This lab was set up to test CVE-2023-33733.
You can see our analyzing process about this CVE in PDF file on main repo.
pip3 install -r requirements.txt
python3 app.py
Connect to server IP address
http://{Server_IP}:4444
After running, you will see an interface like this, you can upload malicious HTML file to see the RCE.

nc -lvnp 4444
Then, upload your evil.html and get the reverse shell
