CyberRota Analysis
AI-GeneratedThe Stirling-PDF web application prior to version 2.0.0 is vulnerable due to improper HTML encoding and sanitization of PDF Title and Author metadata fields, which can lead to the execution of malicious JavaScript in users' browsers. This vulnerability poses a medium risk as it could allow attackers to execute arbitrary scripts, potentially compromising user data or session information. Organizations using Stirling-PDF should prioritize upgrading to version 2.0.0 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Title and Author metadata fields without proper HTML encoding or sanitization, allowing a crafted PDF to execute attacker-controlled JavaScript in the browser of a user who views the resulting page. This issue is fixed in version 2.0.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)