First published: Thu Apr 04 2024(Updated: )
macro-pdfviewer is a PDF Viewer Macro for XWiki using Mozilla pdf.js. Users with edit rights can access restricted PDF attachments using the PDF Viewer macro, just by passing the attachment URL as the value of the ``file`` parameter. Users with view rights can access restricted PDF attachments if they are shown on public pages where the PDF Viewer macro is called using the attachment URL instead of its reference. This vulnerability has been patched in version 2.5.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
XWiki PDF Viewer Macro | <2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-30263 has been classified as a high severity vulnerability due to the ability of unauthorized users to access restricted PDF attachments.
To fix CVE-2024-30263, upgrade the XWiki PDF Viewer Macro to version 2.5.1 or later.
Users with edit rights in XWiki are affected by CVE-2024-30263 as they can exploit the vulnerability to access restricted PDFs.
CVE-2024-30263 potentially exposes sensitive PDF attachments to unauthorized users, compromising data confidentiality.
Currently, the recommended solution is to upgrade to a secure version, as there are no known workarounds for CVE-2024-30263.