CVE-2022-32265
MEDIUMCVSS 5.3/10EPSS 1.17%
Last modified
CVE-2022-32265 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qdecoder Project | Qdecoder | < 12.1.0 |
References
- https://github.com/wolkykim/qdecoder/pull/29Patch, Third Party Advisory
- https://github.com/wolkykim/qdecoder/releases/tag/v12.1.0Release Notes, Third Party Advisory
- https://github.com/wolkykim/qdecoder/pull/29Patch, Third Party Advisory
- https://github.com/wolkykim/qdecoder/releases/tag/v12.1.0Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32265?
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
How severe is CVE-2022-32265?
CVE-2022-32265 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.17% probability of exploitation in the next 30 days.
How do I fix CVE-2022-32265?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3226An OS command injection vulnerability allows admins to execu…7.2
- CVE-2022-32260A vulnerability has been identified in SINEMA Remote Connect…9.8
- CVE-2022-32261A vulnerability has been identified in SINEMA Remote Connect…7.5
- CVE-2022-32262A vulnerability has been identified in SINEMA Remote Connect…9.8
- CVE-2022-32263Pexip Infinity before 28.1 allows remote attackers to trigge…7.5
- CVE-2022-32264sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a den…7.5
- CVE-2022-32266DMA attacks on the parameter buffer used by a software SMI h…6.4
- CVE-2022-32267DMA transactions which are targeted at input buffers used fo…6.4
- CVE-2022-32268StarWind SAN and NAS v0.2 build 1914 allow remote code execu…8.8
- CVE-2022-32269In Real Player 20.0.8.310, the G2 Control allows injection o…9.8
- CVE-2022-32270In Real Player 20.0.7.309 and 20.0.8.310, external::Import()…9.8
- CVE-2022-32271In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbi…9.6
Are you affected by CVE-2022-32265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
