CVE-2024-52299
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2024
Last modified:
18/11/2024
Description
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Any user with view right on XWiki.PDFViewerService can access any attachment stored in the wiki as the "key" that is passed to prevent this is computed incorrectly, calling skip on the digest stream doesn't update the digest. This is fixed in 2.5.6.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:xwiki:pdf_viewer_macro:*:*:*:*:pro:*:*:* | 2.5.6 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



