CVE-2022-23935

HIGH

ExifTool <12.38 - Command Injection

Title source: llm

Description

lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.

Exploits (6)

nomisec WORKING POC 11 stars
by BKreisel · poc
https://github.com/BKreisel/CVE-2022-23935
nomisec WORKING POC 8 stars
by cowsecurity · poc
https://github.com/cowsecurity/CVE-2022-23935
nomisec WORKING POC 1 stars
by dpbe32 · poc
https://github.com/dpbe32/CVE-2022-23935-PoC-Exploit
github FAILED
by cowsecurity · pythonpoc
https://github.com/cowsecurity/CVE-Exploits/tree/main/CVE-2022-23935
nomisec WORKING POC
by antisecc · poc
https://github.com/antisecc/CVE-2022-23935
inthewild WORKING POC
poc
https://github.com/0xftw/cve-2022-23935

Scores

CVSS v3 7.8
EPSS 0.2770
EPSS Percentile 96.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
exiftool_project/exiftool < 12.38
Published Jan 25, 2022
Tracked Since Feb 18, 2026