vendor:
Portal
by:
Abysssec Inc
8,8
CVSS
HIGH
File Download Vulnerability
434
CWE
Product Name: Portal
Affected Version From: DOURAN Portal <= V3.9.0.23
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
Douran Portal Multiple Remote Vulnerabilities
The Douran Portal is vulnerable to a file download vulnerability due to improper validation of user-supplied input. An attacker can exploit this vulnerability by sending a specially crafted request to the vulnerable application. This can allow an attacker to download any file from the web server, including sensitive files such as web.config, which can contain database credentials and other sensitive information.
Mitigation:
Ensure that user-supplied input is properly validated and sanitized before being used in the application.