Vulnerability Description
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avanquest | Pdfescape | 3.19.2.2 |
Related Weaknesses (CWE)
References
- https://arxiv.org/pdf/2206.02285.pdfExploit
- https://www.pdfescape.com/open/Product
- https://arxiv.org/pdf/2206.02285.pdfExploit
- https://www.pdfescape.com/open/Product
FAQ
What is CVE-2022-30350?
CVE-2022-30350 is a vulnerability with a CVSS score of 7.5 (HIGH). Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, t...
How severe is CVE-2022-30350?
CVE-2022-30350 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-30350?
Check the references section above for vendor advisories and patch information. Affected products include: Avanquest Pdfescape.