CVE Database
/

CVE-2022-35649

Back to search

CVE-2022-35649

Published: Jul 25, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

VendorProductVersions

n/a

Moodle

affected
Fixed in moodle 4.0.2, moodle 3.11.8, moodle 3.9.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now