CRITICAL🇵🇱 Wersja polska

CVE-2024-52300

CVSS 9.0v3.1pub. 2024-11-13upd. 2024-11-18

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.

🤖 AI Analysis
How it works

The width parameter of the PDF Viewer macro is not properly escaped before display in the browser, which allows embedding of arbitrary JavaScript code (XSS). Any user with permissions to edit the page can inject a malicious payload into the value of this parameter. The attack requires user interaction — specifically a visit by an administrator to the prepared page, which classifies it as stored XSS with privilege escalation. Due to the scope of the script's operation in the context of an administrator's session, it is possible to take control of the entire XWiki installation.

Impact

An attacker can compromise the confidentiality, integrity, and availability of the entire XWiki installation by performing arbitrary actions in the context of an administrator's session who visits the page with malicious code.

Mitigation & patch

The macro-pdfviewer macro should be updated to version 2.5.6 or newer, in which the vulnerability has been fixed.

Who is affected

The macro-pdfviewer macro (PDF Viewer Macro for XWiki) — versions prior to 2.5.6.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Xwiki Pdf Viewer Macro

    APP
    Xwiki
    < 2.5.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-52298HIGH7.5same product

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker ...

CVE-2024-52299HIGH7.5same product

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFVie...

CVE-2025-24893CRITICAL9.8⚠ KEVPL ✓same vendor

XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch

CVE-2025-65091CRITICAL10.0PL ✓same vendor

SQL Injection w XWiki Full Calendar Macro — dostęp bez uwierzytelnienia

CVE-2025-55727CRITICAL10.0PL ✓same vendor

XWiki Pro Macros: RCE przez brak escapowania parametru width w makro column