From Open Redirect to JavaScript Execution via CVE-2024-4367
Abstract
This case study presents a forensically documented analysis of a multi-stage security incident involving CVE-2024-4367, an arbitrary JavaScript execution vulnerability in PDF.js. The incident occurred on one PKP Open Journal Systems (OJS) deployment. The observed chain involved an open redirect in the host platform's sign-out handler (CWE-601), a prefix-match URL validation weakness in the PDF.js viewer wrapper, and PDF.js font parsing behavior associated with CVE-2024-4367. The evidence demonstrates execution of attacker-controlled JavaScript in the viewer context and an SEO-poisoning effect; it does not establish a general vulnerability in all OJS, WordPress, Drupal, or enterprise deployments. CVSS scores are reported separately for the identified CVE and are not combined into a fabricated composite score. A defense-in-depth mitigation strategy combining reverse-proxy rules, library patches, and Content Security Policy was deployed and verified.