Record summary

CVE-2019-9632 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHESAFENET CDG - Arbitrary File DownloadCVSS 7.5

ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.

Impact

Attackers can download arbitrary files from the server, potentially leading to information disclosure or further exploitation.

Remediation

Apply the latest security patches or update to the latest version provided by ESAFENET.

Authorspdteam
Template tagscvecve2019esafenetlfivuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:esafenet:electronic_document_security_management_system:v3:*:*:*:*:*:*:*
FOFA: title="电子文档安全管理系统"

Source: ProjectDiscovery

References

2