CVE-2022-35649

CRITICAL9.8EPSS 7.5%

Moodle PostScript Code Injection

發布日:2022/7/26修改日:2024/4/24
也稱為:GHSA-xp2f-9mx3-3c6pBIT-moodle-2022-35649

描述

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)