Stirling-PDF, a locally hosted web application for PDF file operations, contains a reflected cross-site scripting (XSS) vulnerability in versions prior to 2.0.0. The flaw exists in multiple file upload endpoints that render user-supplied filenames directly into HTML without sanitization, allowing attackers to inject malicious JavaScript through crafted filenames. The vulnerability has been remediated in version 2.0.0. The attack requires network access and user interaction, with a CVSS score of 3.1 (LOW) reflecting limited impact—specifically low confidentiality risk with no integrity or availability impact. The attack vector is network-based but demands high attack complexity and user action to execute. An attacker would need to trick a user into uploading a specially crafted file with a malicious filename to trigger the XSS payload in that user's browser. The vulnerability is not currently being exploited in the wild and does not appear on the CISA Known Exploited Vulnerabilities catalog. No public exploit code is readily available, and community attention remains minimal, as evidenced by its inactive status on threat tracking lists. Organizations should prioritize upgrading to version 2.0.0 as a routine security maintenance measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.0CPE matchmatch criteria | cpe:2.3:a:stirlingpdf:stirling_pdf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.