macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The width parameter of the PDF viewer macro isn't properly escaped, allowing XSS for any user who can edit a page. XSS can impact the confidentiality, integrity and availability of the whole XWiki installation when an admin visits the page with the malicious code. This is fixed in 2.5.6.
The width parameter of the PDF Viewer macro is not properly escaped before display in the browser, which allows embedding of arbitrary JavaScript code (XSS). Any user with permissions to edit the page can inject a malicious payload into the value of this parameter. The attack requires user interaction — specifically a visit by an administrator to the prepared page, which classifies it as stored XSS with privilege escalation. Due to the scope of the script's operation in the context of an administrator's session, it is possible to take control of the entire XWiki installation.
An attacker can compromise the confidentiality, integrity, and availability of the entire XWiki installation by performing arbitrary actions in the context of an administrator's session who visits the page with malicious code.
The macro-pdfviewer macro should be updated to version 2.5.6 or newer, in which the vulnerability has been fixed.
The macro-pdfviewer macro (PDF Viewer Macro for XWiki) — versions prior to 2.5.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HXwiki Pdf Viewer Macro
APPXwiki< 2.5.6
Related vulnerabilities
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. The PDF Viewer macro allows an attacker ...
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFVie...
XWiki Platform — niezautoryzowany RCE przez endpoint SolrSearch
SQL Injection w XWiki Full Calendar Macro — dostęp bez uwierzytelnienia
XWiki Pro Macros: RCE przez brak escapowania parametru width w makro column