Stirling-Tools Stirling-PDF Markdown-to-PDF cross site scripting
Published Sep 21, 2024
2.3
LOWCVSS 4.0
EPSS 0.43%
Description
A vulnerability was found in Stirling-Tools Stirling-PDF up to 0.28.3. It has been declared as problematic. This vulnerability affects unknown code of the component Markdown-to-PDF. The manipulation leads to cross site scripting. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 0.29.0 is able to address this issue. It is recommended to upgrade the affected component. The vendor explains that "this functionality was removed in 0.29.0 already" and "we plan to re-add at later date with issue resolved".
Affected products
-
Affected
- 0.28.0
- 0.28.1
- 0.28.2
- 0.28.3
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Stirling-Tools | Stirling-PDF | unknown | Affected
|
- < 0.29.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://drive.google.com/file/d/1J4TnzgzKOEvMck3kpaFuR6zfSVt7YgKu/view?usp=sharing relatedExploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49710 Advisory
- https://vuldb.com/?ctiid.278242 signaturepermissions-requiredPermissions Required
- https://vuldb.com/?id.278242 vdb-entryThird Party Advisory
- https://vuldb.com/?submit.406335 third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://drive.google.com/file/d/1J4TnzgzKOEvMck3kpaFuR6zfSVt7YgKu/view?usp=sharing | relatedExploit | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-49710 | Advisory | |
| https://vuldb.com/?ctiid.278242 | signaturepermissions-requiredPermissions Required | |
| https://vuldb.com/?id.278242 | vdb-entryThird Party Advisory | |
| https://vuldb.com/?submit.406335 | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data