CVE-2024-43426

HIGH

pdfTeX - Info Disclosure

Title source: llm
STIX 2.1

Description

A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.

Scores

CVSS v3 7.5
EPSS 0.0091
EPSS Percentile 75.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1287
Status published
Products (2)
moodle/moodle 0 - 4.1.12Packagist
moodle/moodle 4.1.0 - 4.1.12
Published Nov 07, 2024
Tracked Since Feb 18, 2026