CyberRota Analysis
AI-GeneratedThe vulnerability affects the pdfme schemas in Java versions prior to 5.5.10, allowing attackers to exploit the multiVariableText property panel through unsanitized i18n label values. This cross-site scripting flaw enables the injection of arbitrary JavaScript, which executes when users interact with the Designer and select a vulnerable field. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pdfme schemas before 5.5.10 contains a cross-site scripting vulnerability in the multiVariableText property panel that assigns unsanitized i18n label values to innerHTML. Attackers who control label overrides through options.labels can inject arbitrary JavaScript that executes when users open the Designer and select a multiVariableText field without variable placeholders.