Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via ‘IsNextToken’ in the component ‘src/base/PdfToenizer.cpp’.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18972
Reference (s):
- https://sourceforge.net/p/podofo/tickets/49/

