Vulnerability Description
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wavemaker | Wavemarker Studio | 6.6 |
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/45158ExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45158ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2019-8982?
CVE-2019-8982 is a vulnerability with a CVSS score of 9.6 (CRITICAL). com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
How severe is CVE-2019-8982?
CVE-2019-8982 has been rated CRITICAL with a CVSS base score of 9.6/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-8982?
Check the references section above for vendor advisories and patch information. Affected products include: Wavemaker Wavemarker Studio.