PT-2024-36569 · Pendoc · Pendoc
Jorianwoltjer
·
Published
2024-12-11
·
Updated
2024-12-13
·
CVE-2024-55652
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PenDoc versions prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6
Description
PenDoc is a penetration testing reporting application. An attacker can write a malicious docx template containing expressions that escape the JavaScript sandbox to execute arbitrary code on the system. By default, only users with the
admin role are able to create or update templates. An attacker who can control the contents of the template document is able to execute arbitrary code on the system.Recommendations
For versions prior to commit 1d4219c596f4f518798492e48386a20c6e9a2fe6, update to a version that includes the commit 1d4219c596f4f518798492e48386a20c6e9a2fe6 to resolve the issue. As a temporary workaround, consider restricting access to template creation and update functionality to minimize the risk of exploitation. Avoid using malicious docx templates until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pendoc