PT-2019-12670 · Webpagetest · Wpo Webpagetest
Griffin Francis
·
Publicado
2019-05-17
·
Atualizado
2019-05-21
·
CVE-2019-12161
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WPO WebPageTest version 19.04
Description
The issue allows for Server-Side Request Forgery (SSRF) due to the
ValidateURL function in www/runtest.php not properly handling octal encoding of IP addresses. For example, an IP address like 192.168 can be represented in octal as 0300.0250, which is not correctly considered by the validation.Recommendations
For WPO WebPageTest version 19.04, consider modifying the
ValidateURL function to correctly handle octal encoding of IP addresses to prevent SSRF attacks. As a temporary workaround, restrict access to the www/runtest.php script until a proper fix is implemented.Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wpo Webpagetest