{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-6938","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2024-07-20T06:18:32.405Z","datePublished":"2024-07-21T04:31:04.115Z","dateUpdated":"2024-08-01T21:45:38.384Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2024-07-21T04:31:04.115Z"},"title":"SiYuan PDF PDF.js cross site scripting","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-79","lang":"en","description":"CWE-79 Cross Site Scripting"}]}],"affected":[{"vendor":"n/a","product":"SiYuan","versions":[{"version":"3.1.0","status":"affected"}],"modules":["PDF Handler"]}],"descriptions":[{"lang":"en","value":"A vulnerability has been found in SiYuan 3.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file PDF.js of the component PDF Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-271993 was assigned to this vulnerability."},{"lang":"de","value":"In SiYuan 3.1.0 wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Dabei geht es um eine nicht genauer bekannte Funktion der Datei PDF.js der Komponente PDF Handler. Durch das Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":3.5,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV3_0":{"version":"3.0","baseScore":3.5,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N","baseSeverity":"LOW"}},{"cvssV2_0":{"version":"2.0","baseScore":4,"vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N"}}],"timeline":[{"time":"2024-07-20T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2024-07-20T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2024-07-20T08:23:42.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"guchangan1 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/?id.271993","name":"VDB-271993 | SiYuan PDF PDF.js cross site scripting","tags":["vdb-entry"]},{"url":"https://vuldb.com/?ctiid.271993","name":"VDB-271993 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/?submit.372629","name":"Submit #372629 | SIYuan siyuan-note 3.1.0 XSS","tags":["third-party-advisory"]},{"url":"https://github.com/siyuan-note/siyuan/issues/11650","tags":["issue-tracking"]},{"url":"https://github.com/siyuan-note/siyuan/issues/11949","tags":["exploit","issue-tracking"]}]},"adp":[{"affected":[{"vendor":"b3log","product":"siyuan","cpes":["cpe:2.3:a:b3log:siyuan:3.1.0:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"3.1.0","status":"affected"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-07-22T16:41:28.655980Z","id":"CVE-2024-6938","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-22T16:46:49.045Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T21:45:38.384Z"},"title":"CVE Program Container","references":[{"url":"https://vuldb.com/?id.271993","name":"VDB-271993 | SiYuan PDF PDF.js cross site scripting","tags":["vdb-entry","x_transferred"]},{"url":"https://vuldb.com/?ctiid.271993","name":"VDB-271993 | CTI Indicators (IOB, IOC, TTP, IOA)","tags":["signature","permissions-required","x_transferred"]},{"url":"https://vuldb.com/?submit.372629","name":"Submit #372629 | SIYuan siyuan-note 3.1.0 XSS","tags":["third-party-advisory","x_transferred"]},{"url":"https://github.com/siyuan-note/siyuan/issues/11650","tags":["issue-tracking","x_transferred"]},{"url":"https://github.com/siyuan-note/siyuan/issues/11949","tags":["exploit","issue-tracking","x_transferred"]}]}]}}