CVE-2022-34482: Malicious File Upload
Published Jun 28, 2022
·Updated
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34483.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<102
102
Mozilla Firefox<102.0
Event History
Jun 28, 2022
CVE Published
12:00 AM
Dec 22, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2022-34482?
CVE-2022-34482 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2022-34482?
To fix CVE-2022-34482, update your Mozilla Firefox to version 102.0 or later.
3
Who is affected by CVE-2022-34482?
CVE-2022-34482 affects users of Mozilla Firefox versions prior to 102.
4
What type of vulnerability is CVE-2022-34482?
CVE-2022-34482 is a drag-and-drop file handling vulnerability.
5
Can CVE-2022-34482 lead to code execution?
Yes, CVE-2022-34482 can potentially lead to unexpected code execution if exploited.