Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j395-6955-mv56

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

EPSS

Процентиль: 0%
0.00005
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.8
nvd
около 6 лет назад

Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.

EPSS

Процентиль: 0%
0.00005
Низкий

Дефекты

CWE-20