PT-2022-21190 · Qdecoder · Qdecoder

Giulio De Pasquale

+1

·

Published

2022-06-03

·

Updated

2022-06-13

·

CVE-2022-32265

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions qDecoder versions prior to 12.1.0
Description The issue arises from the failure to ensure that the percent character is followed by two hex digits for URL decoding. This can lead to potential security issues.
Recommendations For versions prior to 12.1.0, update to version 12.1.0 or later to resolve the issue. As a temporary workaround, consider implementing additional validation for URL decoding to ensure the percent character is properly followed by two hex digits.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2022-32265

Affected Products

Qdecoder