CVE-2024-52300
Last modified
CVE-2024-52300 is a critical-severity vulnerability rated 9/10 on the CVSS scale. macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Pdf Viewer Macro | < 2.5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-52300?
How severe is CVE-2024-52300?
How do I fix CVE-2024-52300?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-52295DataEase is an open source data visualization analysis tool.…9.8
- CVE-2024-52296libosdp is an implementation of IEC 60839-11-5 OSDP (Open Su…6.5
- CVE-2024-52297Tolgee is an open-source localization platform. Tolgee 3.81.…7.5
- CVE-2024-52298macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozill…7.5
- CVE-2024-52299macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozill…7.5
- CVE-2024-5230A vulnerability has been found in EnvaySoft FleetCart up to …6.9
- CVE-2024-52301Laravel is a web application framework. When the register_ar…7.5
- CVE-2024-52302common-user-management is a robust Spring Boot application f…8.7
- CVE-2024-52303aiohttp is an asynchronous HTTP client/server framework for …8.7
- CVE-2024-52304aiohttp is an asynchronous HTTP client/server framework for …7.5
- CVE-2024-52305UnoPim is an open-source Product Information Management (PIM…4.8
- CVE-2024-52306FileManager provides a Backpack admin interface for files an…9.8
Are you affected by CVE-2024-52300?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
