Sploitus

CVE-2024-52300

No indexed exploits for CVE-2024-52300 yet

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.

Affected products
Pdf.Js
Xwiki Pdf Viewer Macro
< 2.5.6
Fix
Available
CVSS 3.1
9.0 CRITICAL
EPSS
0.4% (36th percentile)
Weakness
CWE-79, CWE-80
NVD status
Analyzed
Published
2024-11-13
CVE-2024-52300 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-52300 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-52300 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.