What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.
Explanation of Vulnerability in Simple Terms
e2pdf versions up to 1.32.14 contain a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts into web pages viewed by other users. The vulnerability requires user interaction—typically clicking a malicious link—and can affect multiple users across the site. Upgrade to version 1.32.15 or later to remediate.
What an attacker can do
Inject malicious JavaScript that runs in other users' browsers and steals session data or performs actions on their behalf.
Potential impact on your site
Visitors can be redirected, have their sessions hijacked, or see defaced content depending on the attacker's payload.
Conditions required to exploit
Attacker must craft a malicious link and trick a user into clicking it; no authentication required.
Key dates
External resources
Related vulnerabilities