CVE-2022-30351
Last modified
CVE-2022-30351 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded in the PDF file, to be leaked unintentionally. In cases where PDF text objects are present it is possible to copy-paste redacted information into the system clipboard. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to correctly remove redacted information from a supplied PDF file, does not properly sanitize this information in all cases, causing redacted information, including images and text embedded in the PDF file, to be leaked unintentionally. In cases where PDF text objects are present it is possible to copy-paste redacted information into the system clipboard. Once a document is "locked" and marked for redaction once, all redactions performed after this feature is triggered are vulnerable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pdfzorro | Pdfzorro | r20220428 |
References
- https://arxiv.org/pdf/2206.02285.pdfThird Party Advisory
- https://arxiv.org/pdf/2206.02285.pdfThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-30351?
How severe is CVE-2022-30351?
How do I fix CVE-2022-30351?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-30338Incorrect default permissions in the Intel(R) VROC software …7.8
- CVE-2022-30339Out-of-bounds read in firmware for the Intel(R) Integrated S…4.4
- CVE-2022-3034When receiving an HTML email that specified to load an <code…4.3
- CVE-2022-30349siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripti…6.1
- CVE-2022-3035Cross-site Scripting (XSS) - Stored in GitHub repository sni…4.8
- CVE-2022-30350Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vu…7.5
- CVE-2022-30352phpABook 0.9i is vulnerable to SQL Injection due to insuffic…9.8
- CVE-2022-30354OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data…7.5
- CVE-2022-30355OvalEdge 5.2.8.0 and earlier is affected by an Account Takeo…9.8
- CVE-2022-30356OvalEdge 5.2.8.0 and earlier is affected by a Privilege Esca…4.7
- CVE-2022-30357OvalEdge 5.2.8.0 and earlier is affected by an Account Takeo…8.8
- CVE-2022-30358OvalEdge 5.2.8.0 and earlier is affected by an Account Takeo…8.8
Are you affected by CVE-2022-30351?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
