PT-2021-22515 · Pdftron · Webviewer Ui
Published
2021-09-15
·
Updated
2021-09-30
·
CVE-2021-39307
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
PDFTron's WebViewer UI versions 8.0 and below
Description:
The issue allows the execution of arbitrary JavaScript code due to the rendering of dangerous URLs, including JavaScript URLs, as hyperlinks in supported documents.
Recommendations:
For versions 8.0 and below, consider disabling the rendering of hyperlinks for JavaScript URLs as a temporary workaround until a patch is available. Restrict access to documents that may contain malicious URLs to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webviewer Ui