CVE-2022-39016: Cross Site Scripting (XSS)

DESCRIPTION:

PDF documents uploaded to Hubshare render dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code. The Hubshare application appears to use a vulnerable version of PDFTron Webviewer UI for document viewing, collaboration and annotation

AFFECTED PRODUCTS:

* Hubshare

MORE INFORMATION:

The issue has been naturally fixed by upgrading the Pdftron Viewer library. No hubshare source code changes needed.

Acknowledgement:

We thank Michael Newton <mnewton@themissinglink.com.au> for responsible disclosure.

Date issued: 2022-08