Vulnerabilities/

Cross-site Scripting in electron-pdf

Severity:
High

Description

electron-pdf version 20.0.0 allows an external attacker to remotely obtain

arbitrary local files. This is possible because the application does not

validate the HTML content entered by the user.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
electron-pdf
Anything's wrong? Let us know Last updated on February 21, 2024

This issue is available in SmartScanner Professional

See Pricing