We're sorry AsposeCloud doesn't work properply without JavaScript enabled.

Free Support Forum - aspose.cloud

PDF injection vulnerability

Hi,

I was asked a security question around use of aspose cloud to generate PDFs, and whether the API will check for injection attacks.

https://portswigger.net/research/portable-data-exfiltration

Does the aspose cloud pdf api prevent such attacks, or is more work required in my own software to mitigate against them.

Thanks,

Dan.

@thebirdmanloves

We are investigating(PDFCLOUD-2363) your raised question and will share our findings with you asap.

@thebirdmanloves

Please note we have already solved the possibility of such injection in PDF documents. So Aspose.PDF Cloud is safe to XXE and XSS injection vulnerability.

1 Like

Great thanks for coming back so quickly @tilal.ahmad!

1 Like