Vulnerability Description
Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this can have a security risk if debug.log is later edited and then executed.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gonitro | Nitro Pro | < 13.2 |
Related Weaknesses (CWE)
References
- https://a-man-in-the-cookie.blogspot.com/2019/11/nitro-pro-vulnerability.htmlExploitThird Party Advisory
- https://a-man-in-the-cookie.blogspot.com/2019/11/nitro-pro-vulnerability.htmlExploitThird Party Advisory
FAQ
What is CVE-2019-18958?
CVE-2019-18958 is a vulnerability with a CVSS score of 7.8 (HIGH). Nitro Pro before 13.2 creates a debug.log file in the directory where a .pdf file is located, if the .pdf document was produced by an OCR operation on the JPEG output of a scanner. Reportedly, this ca...
How severe is CVE-2019-18958?
CVE-2019-18958 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-18958?
Check the references section above for vendor advisories and patch information. Affected products include: Gonitro Nitro Pro.