com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2019-02-21T14:00:00Z

Updated: 2024-09-16T18:48:39.625Z

Reserved: 2019-02-21T00:00:00Z

Link: CVE-2019-8982

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-02-21T14:29:00.423

Modified: 2019-02-21T19:56:24.747

Link: CVE-2019-8982

cve-icon Redhat

No data.