GHSA-jm43-hrq7-r7w6
HIGHCVE-2025-49580Pages can gain script or programming rights when they contain a link and the target of the link is renamed or moved. This might lead to execution of scripts contained in xobjects that should have never been executed.
- Affected
- >= 7.4.5, < 8.0-milestone-1, >= 8.2, < 16.4.7, >= 16.5.0-rc-1, < 16.10.4, >= 17.0.0-rc-1, < 17.1.0-rc-1
- Fixed in
- 16.4.7
- Weakness
- CWE-266
- Published
- 2025-06-13
- Source
- github