Vulnerabilities > CVE-2023-30802 - Exposure of Resource to Wrong Sphere vulnerability in Sangfor Next-Gen Application Firewall 8.0.17

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sangfor
CWE-668

Summary

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.

Vulnerable Configurations

Part Description Count
Application
Sangfor
1

Common Weakness Enumeration (CWE)