Steps to reproduce :
- create a File document with the attached PDF : payload1.pdf
- observe that a javascript popup is displayed: it corresponds to an example of malicious script included in the PDF which is displayed by the previewer (pdf.js)
Expected behavior: the malicious script included in a PDF are not executed during the preview
- is related to
-
WEBUI-1532 [PDF.js] Analyze and fix CVE-2024-4367 with PDF.js
- Open