CVE-2024-50344
MEDIUMI, Librarian <5.11.2 - Supplemental File Cross-Site Scripting
Title source: manualDescription
I, Librarian is an open-source version of a PDF managing SaaS. Supplemental Files are allowed to be viewed in the browser, only if they have a white-listed MIME type. Unfortunately, this logic is broken, thus allowing unsafe files containing Javascript to be executed with the application context. An attacker can exploit this vulnerability by uploading a supplementary file that contains a malicious code or script. This code will then be executed when the file is loaded in the browser. The vulnerability was fixed in version 5.11.2.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/mkucej/i-librarian-free/security/advisories/GHSA-c2rm-w62w-5xmj
Scores
CVSS v3
4.6
EPSS
0.0028
EPSS Percentile
19.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
Status
published
Products (1)
mkucej/i-librarian-free
< 5.11.2
Published
Oct 30, 2024
Tracked Since
Feb 18, 2026