Vulnerabilities > CVE-2019-8982 - Server-Side Request Forgery (SSRF) vulnerability in Wavemaker Wavemarker Studio 6.6

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
wavemaker
CWE-918
exploit available

Summary

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

Vulnerable Configurations

Part Description Count
Application
Wavemaker
1

Common Weakness Enumeration (CWE)

Exploit-Db

idEDB-ID:45158