Account Takeover via Malicious PDF

linkResolution: ❌

Duplicate

Reports that do not describe a security issue

Browsers sandbox PDF javascript (alert is still allowed)

PDF content is already served from an isolated domain


linkReport

I identified a potential vulnerability in the PDF upload/rendering functionality. An attacker can upload a specially crafted PDF through the application's PDF upload functionality and subsequently deliver that PDF to another user. When the victim opens the PDF through the application's trusted PDF delivery/viewing flow, attacker-controlled content is rendered in the victim's browser.
 
Under the vulnerable rendering conditions, attacker-controlled JavaScript can execute in the victim's browser context. This could potentially allow an attacker to perform actions as the victim, access information available to the application's JavaScript context, present a convincing re-authentication/phishing interface, or potentially achieve account takeover depending on the application's authentication architecture.
 
PortSwigger has documented that XSS can allow attacker-controlled JavaScript to execute in a victim's browser and perform actions available to that user. Their PDF research also demonstrates that PDF processing/rendering can introduce JavaScript execution and data-exfiltration risks.
 
Reproduction step
 
1. Create a harmless test PDF from https://github.com/zack0x01/XSS.pdf-Credential-Harvesting-PDF
 
2. . Send the uploaded PDF note to another test account you control.
 
3. Open the PDF in Chrome through the website's normal PDF viewer.
 
4. you will see PDF executes, the vulnerability is reproduced. and enter you email and password and then you will check in https://webhook.site/
 
Note: Prevent JavaScript execution in uploaded PDFs and serve them from an isolated, untrusted domain. Also sanitize uploaded PDFs before rendering.
 
Remediation :
 
1. Prevent JavaScript from executing inside uploaded PDFs.
 
2. Use secure headers such as Content-Security-Policy and X-Content-Type-Options: nosniff
 
3. Sanitize PDFs before storing/rendering them