CVE-2019-9632
ESAFENET CDG - Arbitrary File Download
Record summary
CVE-2019-9632 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHESAFENET CDG - Arbitrary File DownloadCVSS 7.5
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
Impact
Attackers can download arbitrary files from the server, potentially leading to information disclosure or further exploitation.
Remediation
Apply the latest security patches or update to the latest version provided by ESAFENET.
Source: ProjectDiscovery