PT-2024-36569 · Pendoc · Pendoc

Jorianwoltjer

·

Published

2024-12-11

·

Updated

2024-12-13

·

CVE-2024-55652

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PenDoc versions prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6
Description PenDoc is a penetration testing reporting application. An attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. By default, only users with the admin role are able to create or update templates. An attacker who can control the contents of the template document is able to execute arbitrary code on the system.
Recommendations For versions prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, update to a version that includes the commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 to resolve the issue. As a temporary workaround, consider restricting access to template creation and update functionality to minimize the risk of exploitation. Avoid using malicious docx templates until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55652
GHSA-JW5R-6927-HWPC

Affected Products

Pendoc