Vulnerabilities > CVE-2019-8982 - Server-Side Request Forgery (SSRF) vulnerability in Wavemaker Wavemarker Studio 6.6

047910
CVSS 9.6 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
wavemaker
CWE-918
critical
exploit available

Summary

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

Vulnerable Configurations

Part Description Count
Application
Wavemaker
1

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:45158