VulnerabilityDeferred
CVE-2024-41943
An attacker can exploit this vulnerability by inserting a payload in the PDF notes that contains malicious code or script.
MEDIUM 4.6EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
I, Librarian is an open-source version of a PDF managing SaaS. PDF notes are displayed on the Item Summary page without any form of validation or sanitation. An attacker can exploit this vulnerability by inserting a payload in the PDF notes that contains malicious code or script. This code will then be executed when the page is loaded in the browser. The vulnerability was fixed in version 5.11.1.
- CVSS 3.1
- 4.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Source
- security-advisories@github.com
References
- https://github.com/mkucej/i-librarian-free/commit/b4570103d21fc4fdd2483689aafc6028d9f6a76d
- https://github.com/mkucej/i-librarian-free/security/advisories/GHSA-h5hx-fm7f-2xmx
- https://github.com/mkucej/i-librarian-free/commit/b4570103d21fc4fdd2483689aafc6028d9f6a76d
- https://github.com/mkucej/i-librarian-free/security/advisories/GHSA-h5hx-fm7f-2xmx
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.