
Research
/Security News
Critical Vulnerability in NestJS Devtools: Localhost RCE via Sandbox Escape
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
smmapdfs is used for generating pdf files from django models by overlaying the text of fields onto a background pdf file. It differs from other django pdf apps such as django-easy-pdf <https://django-easy-pdf.readthedocs.io/en/v0.2.0-dev1/>
_ and django-pdfkit <https://github.com/alexhayes/django-pdfkit>
_ in that it is intended to be used by graphics designers wishing to overlay some text onto a pre-prepaired pdf background.
smmapdfs can further be used to send out emails with the pdfs. It was initially intended to send out diplomas at the end of a cycling competition.
.. image:: ./play.png :target: https://ipfstube.erindachtler.me/v/QmWuK5zvq3h1CHr4P1ZYUQ6HPidF9NYHhmmXzNf5XsVRnU
Sudo make me a pfd sandwich is published on Pypy as django-smmapdfs <https://pypi.org/project/django-smmapdfs/>
_.
pip3 install django-smmapdfs
See the example app for an example of how to integrate smmapdfs into your django application.
In smmapdfs admin:
In your application's admin:
In your application's admin
The emails are sent as HTML messages. Text messages are created by stripping out the HTML tags. This means that links should be written in their full form.
Please remember, both the United states and the EU have criminal penalties for sending unsolicited SPAM email messages. This app is not designed or intended for such a purpose. Please do not use it to send SPAM. (This note has no legal implications for licensing purposes. The software is licensed under the GNU LGPLv3.0)
FAQs
Generate PDFs from django models by overlaying text onto an existing pdf
We found that django-smmapdfs demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
/Security News
A flawed sandbox in @nestjs/devtools-integration lets attackers run code on your machine via CSRF, leading to full Remote Code Execution (RCE).
Product
Customize license detection with Socket’s new license overlays: gain control, reduce noise, and handle edge cases with precision.
Product
Socket now supports Rust and Cargo, offering package search for all users and experimental SBOM generation for enterprise projects.