Lucene search

K
cvelistFedoraCVELIST:CVE-2022-35649
HistoryJul 25, 2022 - 3:27 p.m.

CVE-2022-35649

2022-07-2515:27:27
CWE-94
fedora
www.cve.org
2
moodle
postscript code
input validation
remote code execution
ghostscript

AI Score

9.8

Confidence

High

EPSS

0.03

Percentile

91.0%

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CNA Affected

[
  {
    "product": "Moodle",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Fixed in moodle 4.0.2, moodle 3.11.8, moodle 3.9.15"
      }
    ]
  }
]

AI Score

9.8

Confidence

High

EPSS

0.03

Percentile

91.0%