CVE-2019-8982
CRITICAL EXPLOITED NUCLEIWaveMaker Studio 6.6 - Server-Side Request Forgery via studioService.download inUrl Parameter
Title source: llmExploitation Summary
CVE-2019-8982 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Gionathan Reale. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Server-Side Request Forgery (SSRF) vulnerability in Wavemaker Studio 6.6, allowing an attacker to access internal resources or external URLs via the `inUrl` parameter in the `studioService.download` endpoint.
Description
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
Exploits (1)
This exploit demonstrates a Server-Side Request Forgery (SSRF) vulnerability in Wavemaker Studio 6.6, allowing an attacker to access internal resources or external URLs via the `inUrl` parameter in the `studioService.download` endpoint.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H