PDF Signer 3.0 - SSTI to RCE via CSRF Cookie Vulnerability

By
Anandhu K A
Published on
01 Oct 2021
Vulnerability

PDF Signer version 3.0 was affected by Server-Side Template Injection leading to Remote Command Execution due to improper Cookie handling and improper CSRF implementation.

Impact

A remote attacker can use this vulnerability to execute arbitrary commands.

Mitigation / Precaution

In order to patch this vulnerability, we recommend you to update PDF Signer to the latest version.


Written by
Anandhu K A
Anandhu K A
Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days