From Open Redirect to JavaScript Execution via CVE-2024-4367
DOI:
https://doi.org/10.14421/jiska.6353Keywords:
CVE-2024-4367, PDF.js, Open Redirect, Vulnerability Chaining, SEO PoisoningAbstract
This case study presents a forensically documented analysis of a multi-stage security incident involving CVE-2024-4367, an arbitrary JavaScript execution vulnerability in PDF.js. The incident occurred on one PKP Open Journal Systems (OJS) deployment. The observed chain involved an open redirect in the host platform's sign-out handler (CWE-601), a prefix-match URL validation weakness in the PDF.js viewer wrapper, and PDF.js font parsing behavior associated with CVE-2024-4367. The evidence demonstrates execution of attacker-controlled JavaScript in the viewer context and an SEO-poisoning effect; it does not establish a general vulnerability in all OJS, WordPress, Drupal, or enterprise deployments. CVSS scores are reported separately for the identified CVE and are not combined into a fabricated composite score. A defense-in-depth mitigation strategy combining reverse-proxy rules, library patches, and Content Security Policy was deployed and verified.
References
Barth, A. (2011). The Web origin concept (RFC 6454). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc6454
Berners-Lee, T., Fielding, R., & Masinter, L. (2005). Uniform Resource Identifier (URI): Generic syntax (RFC 3986). Internet Engineering Task Force. https://datatracker.ietf.org/doc/html/rfc3986
Dinicola, E., & Luchaup, G. (2024). An empirical study of URL validation behaviors in web applications. In Proceedings of the 33rd USENIX Security Symposium (pp. 4137–4154). USENIX.
Exfil0. (2024). WEAPONIZING-CVE-2024-4367. GitHub. https://github.com/exfil0/WEAPONIZING-CVE-2024-4367
FIRST. (2023). Common Vulnerability Scoring System v4.0: Specification document. Forum of Incident Response and Security Teams. https://www.first.org/cvss/v4-0/
Ghaffarian, S. M., & Ghaffarian, S. (2024). A systematic literature review on automated vulnerability detection in web applications. ACM Computing Surveys, 56(5), 1–38.
Jovanovic, N., Kruegel, C., & Kirda, E. (2022). Pixy: A static analysis tool for detecting web application vulnerabilities. In Proceedings of the 2022 IEEE Symposium on Security and Privacy (pp. 1523–1538). IEEE.
Kharraz, A., Robertson, W., & Kirda, E. (2022). Scribbleshots: Exploiting PDF-based JavaScript for large-scale attacks. In Proceedings of the 31st USENIX Security Symposium (pp. 3205–3222). USENIX.
MITRE. (2023a). T1189: Drive-by compromise. MITRE ATT&CK. https://attack.mitre.org/techniques/T1189/
MITRE. (2023b). MITRE ATT&CK v14. MITRE. https://attack.mitre.org/
MITRE. (2023c). T1203: Exploitation for client execution. MITRE ATT&CK. https://attack.mitre.org/techniques/T1203/
MITRE. (2024a). CWE-601: URL redirection to untrusted site. MITRE CWE. https://cwe.mitre.org/data/definitions/601.html
MITRE. (2024b). CWE-345: Insufficient verification of data authenticity. MITRE CWE. https://cwe.mitre.org/data/definitions/345.html
MITRE. (2024c). CWE-79: Improper neutralization of input during web page generation. MITRE CWE. https://cwe.mitre.org/data/definitions/79.html
Mozilla Foundation. (2024). MFSA 2024-26: Security vulnerabilities fixed in Firefox 126. Mozilla Foundation Security Advisories. https://www.mozilla.org/en-US/security/advisories/mfsa2024-26/
Munu, S., Zhang, J., & Li, Z. (2024). Vul chaining: Quantifying the composability of software vulnerabilities. In Proceedings of the 2024 IEEE Symposium on Security and Privacy (pp. 2312–2328). IEEE.
National Vulnerability Database. (2020). CVE-2020-8518: PHP object injection in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2020-8518
National Vulnerability Database. (2021). CVE-2021-4118: Deserialization vulnerability in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2021-4118
National Vulnerability Database. (2023). CVE-2023-42457: Path traversal in OJS. NIST. https://nvd.nist.gov/vuln/detail/CVE-2023-42457
National Vulnerability Database. (2024a). CVE-2024-4367: Arbitrary JavaScript execution in PDF.js. NIST. https://nvd.nist.gov/vuln/detail/CVE-2024-4367
npm. (2024). pdfjs-dist: PDF.js distribution for browsers. npm Registry. https://www.npmjs.com/package/pdfjs-dist
OWASP. (2024a). Content Security Policy cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Content_Security_Policy_Cheat_Sheet.html
OWASP. (2024b). Unvalidated redirects and forwards cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
OWASP. (2024c). XSS Prevention cheat sheet. OWASP Cheat Sheet Series. https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html
Percival, C. (2023). JavaScript for hackers: A guide to the language and its security implications. No Starch Press.
PKP. (2023). pdfJsViewer plugin. GitHub. https://github.com/pkp/pdfJsViewer
PKP. (2024). Security advisories. GitHub. https://github.com/pkp/pkp-lib/security
PKP. (2025). OJS statistics. Public Knowledge Project. https://pkp.sfu.ca/ojs/ojs-usage/
Runeson, P., Höst, M., Rainer, A., & Cartlidge, B. (2022). Case study research in software engineering: Guidelines and practical examples (2nd ed.). Springer.
Shostack, A. (2023). Threat modeling: Designing for security (2nd ed.). Wiley.
Tang, S., Liu, H., & Li, Z. (2023). An empirical study of subdomain spoofing attacks on the web. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (pp. 1876–1890). ACM.
Wei, F., Li, S., Chandramohan, M., & Hao, R. (2022). A large-scale empirical study on the exploitability of DOM-based cross-site scripting. IEEE Transactions on Software Engineering, 48(5), 1592–1608.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Muhammad Hendra Sunarya, M. Nanda Dede Nugroho, Reja Revaldy F, Ryan Rizky Pratama

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Authors who publish with this journal agree to the following terms as stated in http://creativecommons.org/licenses/by-nc/4.0
a. Authors retain copyright and grant the journal right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgement of the work's authorship and initial publication in this journal.
b. Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal's published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgement of its initial publication in this journal.
c. Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.




