webPromedium
DocuVault — Stored XSS via Malicious PDF (CVE-2024-4367)
hackadvisor
Task: Document sharing platform with in-browser PDF rendering via pdf.js 4.1.392, admin bot reviews shared documents. Solution: CVE-2024-4367 — inject JavaScript via malicious FontMatrix string in PDF font dictionary, exfiltrate admin cookie containing flag.
$ ls tags/ techniques/
admin_bot_cookie_exfiltrationhoneypot_flag_detectioncve_2024_4367_pdfjs_fontmatrix_injectiontruetype_unitsperem_zero_bypasstext_rendering_mode_add_to_pathstored_xss_via_pdf_uploadinteract_server_path_exfiltration
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 342 — CloudVault — Stored XSS via Malicious SVG Upload— hackadvisor
- [web][Pro]Lab 346 — DropVault — Path Traversal via Tar Symlink Cache Poisoning— hackadvisor
- [web][Pro]Lab 393 — ShareVault — Stored XSS via File Browser innerHTML— hackadvisor
- [web][Pro]InkDrop— hackadvisor
- [web][Pro]DocuNest— hackadvisor