CVE-2022-30351 describes a data leakage vulnerability in PDFZorro Online (r20220428), which utilizes TCPDF 6.2.5. Despite claims of secure redaction, the software fails to properly sanitize redacted information, allowing sensitive text and images to be unintentionally leaked, particularly when PDF text objects are present and a document has been "locked" for redaction. The vulnerability carries a CVSS v3.1 score of 7.5 (HIGH), indicating a network-exploitable flaw with low attack complexity and no user interaction required, leading to a high potential for confidentiality impact. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, consistent with the majority of reported vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r20220428CPE matchmatch criteria | cpe:2.3:a:pdfzorro:pdfzorro:r20220428:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.