Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-30263

Опубликовано: 04 апр. 2024
Источник: nvd
CVSS3: 7.7
EPSS Низкий

Описание

macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF attachments using the PDF Viewer macro, just by passing the attachment URL as the value of the file parameter. Users with view rights can access restricted PDF attachments if they are shown on public pages where the PDF Viewer macro is called using the attachment URL instead of its reference. This vulnerability has been patched in version 2.5.1.

EPSS

Процентиль: 22%
0.00073
Низкий

7.7 High

CVSS3

Дефекты

CWE-200

EPSS

Процентиль: 22%
0.00073
Низкий

7.7 High

CVSS3

Дефекты

CWE-200