I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. An attacker can exploit this vulnerability by uploading a supplementary file that contains a malicious code or script. This code will then be executed when the file is loaded in the browser. The vulnerability was fixed in version 5.11.2.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Oct 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 30 Oct 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. An attacker can exploit this vulnerability by uploading a supplementary file that contains a malicious code or script. This code will then be executed when the file is loaded in the browser. The vulnerability was fixed in version 5.11.2. | |
Title | I, Librarian has a Stored XSS vulnerability in Supplemental Files | |
Weaknesses | CWE-80 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-30T15:51:30.047Z
Updated: 2024-10-30T16:02:30.738Z
Reserved: 2024-10-22T17:54:40.955Z
Link: CVE-2024-50344
Vulnrichment
Updated: 2024-10-30T16:02:26.476Z
NVD
Status : Awaiting Analysis
Published: 2024-10-30T16:15:04.763
Modified: 2024-11-01T12:57:03.417
Link: CVE-2024-50344
Redhat
No data.