LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2022-4993

Published
CVSS9.1
Severitycritical
WeaknessCWE-470
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Description

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template. add_error hands its first argument to the language handle as the Locale::Maketext message key, and the default handle's lexicon sets `_AUTO`, so a string that is not a lexicon entry is compiled as a bracket notation template instead of being looked up. In a bracket group the first token names a method called on the language handle and the remaining tokens are its arguments. Three kinds of text the library did not author reach that position. _app

References

← Back to the CVE Tracker

Our coverage of CVE-2022-4993

No stories yet. This page updates automatically when we publish reporting that references CVE-2022-4993.