Lucene search

K
osvGoogleOSV:GHSA-3PXP-6963-46R9
HistoryJun 07, 2018 - 7:43 p.m.

Command Injection in pdfinfojs

2018-06-0719:43:00
Google
osv.dev
9

0.004 Low

EPSS

Percentile

72.4%

Versions of pdfinfojs before 0.4.1 are vulnerable to command injection. This is exploitable if an attacker can control the filename parameter that is passed into the pdfinfojs constructor.

Recommendation

Update to version 0.4.1 or later.

CPENameOperatorVersion
pdfinfojslt0.4.1

0.004 Low

EPSS

Percentile

72.4%