VYPR
Medium severity6.1NVD Advisory· Published Sep 15, 2021· Updated Jun 17, 2026

CVE-2021-39307

CVE-2021-39307

Description

PDFTron's WebViewer UI 8.0 or below renders dangerous URLs as hyperlinks in supported documents, including JavaScript URLs, allowing the execution of arbitrary JavaScript code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:pdftron:webviewer_ui:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pdftron:webviewer_ui:*:*:*:*:*:*:*:*range: <=8.0
    • (no CPE)range: <=8.0
  • PDFTron/WebViewer UIdescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.