CVE-2024-57240 Details
Description
A Cross-Site Scripting (XSS) vulnerability in the Rendering Engine component in Apryse WebViewer v11.1 and earlier allows attackers to execute arbitrary code via a crafted PDF file.
A Cross-Site Scripting (XSS) vulnerability exists in Apryse WebViewer versions 11.1 and earlier, specifically within the PDF Rendering Engine component. This vulnerability allows remote attackers to execute arbitrary JavaScript by crafting a malicious PDF file. The issue stems from inadequate input sanitization during the rendering process.
Users are advised to update Apryse WebViewer to the latest version, where this vulnerability has been fixed. Additionally, implementing a Content Security Policy (CSP) can help mitigate XSS attacks.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/devom3/43c328e23ec854090ed555a13541ca94 | [email protected] | ExploitIssue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| apryse webviewer | <= 11.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2025 | Initial Analysis | [email protected] |
| Mar 4, 2025 | CVE Modified | CISA-ADP |
| Mar 3, 2025 | New CVE Received | [email protected] |