PT-2024-29651 · I · I

Alessio-Romano

·

Published

2024-07-30

·

Updated

2024-07-31

·

CVE-2024-41943

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions I, Librarian versions prior to 5.11.1
Description The issue arises from the lack of validation or sanitation of PDF notes displayed on the Item Summary page. An attacker can exploit this by inserting a malicious payload into the PDF notes, which will be executed when the page is loaded in the browser.
Recommendations For versions prior to 5.11.1, update to version 5.11.1 to resolve the issue. As a temporary workaround, consider restricting access to the Item Summary page or disabling the display of PDF notes until the update can be applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-41943
GHSA-H5HX-FM7F-2XMX

Affected Products

I