CVE-2024-52299
HIGHDescription
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesn't update the digest. This is fixed in 2.5.6.
Is your site exposed to CVE-2024-52299?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| xwiki | pdf_viewer_macro |
References
Frequently Asked Questions
What is CVE-2024-52299? +
How severe is CVE-2024-52299? +
What products are affected by CVE-2024-52299? +
How do I check if I'm vulnerable to CVE-2024-52299? +
Related Vulnerabilities
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due …
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation …
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs …
FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.213, attachment download tokens are generated using …
Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with …