Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9xg-3j9r-v8jf

Опубликовано: 30 мар. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.

Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.

EPSS

Процентиль: 29%
0.00104
Низкий

7.5 High

CVSS3

Дефекты

CWE-213

Связанные уязвимости

CVSS3: 7.5
nvd
почти 3 года назад

Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.

EPSS

Процентиль: 29%
0.00104
Низкий

7.5 High

CVSS3

Дефекты

CWE-213