Grooper 21.00.0082 is available as of 12-12-2023! Check the  Downloads Discussion  for the release notes and to get the latest version.
Grooper 23.00.0042 is available as of 03-22-2024! Check the Downloads Discussion for the release notes and to get the latest version.
Grooper 23.1.0018 is available as of 04-15-2024! Check the  Downloads Discussion  for the release notes and to get the latest version.
Options

PDF scripting vulnerabilities

Received the question below from a client...

Do you guys have any experience dealing with cross site scripting vulnerabilities with PDFs? I would assume Grooper negates this by re-rendering all docs and converting them to a different file type. But we wondered if you guys have ever done a project where someone could upload a pdf to a public web portal before Grooper or a similar capture app would import it. In that scenario a malicious user could attack the public web portal with a malicious PDF and use it as an entry point to other things.

We were just brain storming and don’t have any problem we were trying to solve, but our security folks look to BIS as the document experts and wondered what your thoughts on this might be. I’m not looking for anyone to spend hours thinking about this, but if you had any best practices or quick thoughts on the topic we would love to hear them.

Best Answer

Sign In or Register to comment.