vendor:
FileMage Gateway
by:
Bryce "Raindayzz" Harty
7.5
CVSS
HIGH
Local File Inclusion
22
CWE
Product Name: FileMage Gateway
Affected Version From: Azure Versions < 1.10.9
Affected Version To: 1.10.2009
Patch Exists: YES
Related CWE: CVE-2023-39026
CPE: cpe:2.3:a:filemage:gateway:1.10.9
Tags: cve,cve2023,lfi,filemage
Nuclei Metadata: {'max-request': 1, 'verified': True, 'shodan-query': 'title:"FileMage"'}
Platforms Tested: All Azure deployments < 1.10.9
2023
FileMage Gateway 1.10.9 – Local File Inclusion
The FileMage Gateway version 1.10.9 is vulnerable to a local file inclusion vulnerability. An attacker can exploit this vulnerability to include arbitrary files from the server, potentially leading to remote code execution.
Mitigation:
Update to FileMage Gateway version 1.10.9 or later. Restrict access to the vulnerable endpoint and sanitize user input to prevent directory traversal attacks.