fix: pdfjs-content-spoofing template false positive reduction

This commit is contained in:
Eren-Akdag
2026-01-10 04:06:45 +03:00
parent 14068f99e6
commit 5411c9a3cf

View File

@@ -2,7 +2,7 @@ id: pdfjs-content-spoofing
info:
name: Mozilla PDF.js - Content Spoofing
author: 0x_Akoko
author: 0x_Akoko,s4e-io
severity: medium
description: |
Detected PDF.js viewer loads and renders external PDF files without proper origin validation. Versions < v1.3.91 are vulnerable to content spoofing attacks.
@@ -44,7 +44,9 @@ headless:
- type: word
part: body
words:
- "pdf.js"
- "viewerContainer"
- "pdfViewer"
condition: and
- type: word
part: body
@@ -53,5 +55,4 @@ headless:
- "file origin does not match"
- "blocked"
- "Not Found"
condition: or
# digest: 490a0046304402207dc1eb1cfd5bc25039d729f591a15f5a9a37667ed6ad50d1c1c73fe20004b9a8022071080c75bcced708e51b213a2d9887954d7145d3666a5b1de77a04eb08905a67:922c64590222798bb761d5b6d8e72950
condition: or