EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.Referenceshttps://files.eprints.org/2549/https://files.eprints.org/2548/https://github.com/grymer/CVE/blob/master/eprints_security_review.pdf