An arbitrary file download vulnerability in the downloadAction() function of Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to download arbitrary files via a crafted POST request.
References
Link | Resource |
---|---|
https://medium.com/@_sadshade/wapples-web-application-firewall-multiple-vulnerabilities-35bdee52c8fb | Exploit Third Party Advisory |
https://www.pentasecurity.com/product/wapples/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-09-13 15:15
Updated : 2022-09-17 18:16
NVD link : CVE-2022-31324
Mitre link : CVE-2022-31324
JSON object : View
CWE
CWE-494
Download of Code Without Integrity Check
Products Affected
pentasecurity
- wapples