CVE-2022-31246

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/06/2022
Last modified:
28/06/2022

Description

paymentrequest.py in Electrum before 4.2.2 allows a file:// URL in the r parameter of a payment request (e.g., within QR code data). On Windows, this can lead to capture of credentials over SMB. On Linux and UNIX, it can lead to a denial of service by specifying the /dev/zero filename.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:electrum:electrum:*:*:*:*:*:*:*:* 4.2.2 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*