Описание
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-32265
- https://github.com/wolkykim/qdecoder/pull/29
- https://github.com/wolkykim/qdecoder/pull/29/commits/ce7c8a7ac450a823a11b06508ef1eb7441241f81#diff-1c4e2f5adfa1ad30618e78ff459b2c0758ecf34278459ad0a8d58db4fec622ea
- https://github.com/wolkykim/qdecoder/releases/tag/v12.1.0
Связанные уязвимости
CVSS3: 5.3
nvd
больше 3 лет назад
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.