Vulnerabilities
Vulnerable Software
Pdfmake Project:  >> Pdfmake  Security Vulnerabilities
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.
CVSS Score
9.8
EPSS Score
0.006
Published
2024-02-29
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code execution in the context of the process running the pdfmake code. There are no known fixes for this issue. Users are advised to restrict access to trusted user input.
CVSS Score
10.0
EPSS Score
0.056
Published
2022-12-06


Contact Us

Shodan ® - All rights reserved