Skip to content

Instantly share code, notes, and snippets.

@Xib3rR4dAr
Xib3rR4dAr / CVE-2024-57240_Apryse_WebViewer_XSS.md
Created March 13, 2025 09:53 — forked from devom3/CVE-2024-57240_Apryse_WebViewer_XSS.md
CVE-2024-57240: Cross-Site Scripting (XSS) Vulnerability in Apryse WebViewer <= 11.1

CVE-2024-57240: Cross-Site Scripting (XSS) Vulnerability in Apryse WebViewer ≤ 11.1

Date Published: Feb 24 2025

Summary

A Cross-Site Scripting (XSS) vulnerability has been identified in Apryse WebViewer versions up to and including 11.1. This vulnerability allows remote attackers to execute arbitrary JavaScript code by supplying a crafted PDF file. The issue arises due to improper sanitization of user-supplied input during PDF rendering.

Affected Product