If pdf.js is used to load a malicious PDF, and PDF.js is configured with isEvalSupported set to true (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.
This Cyber News was published on www.tenable.com. Publication date: Wed, 08 May 2024 06:56:03 +0000