PT-2019-12670 · Webpagetest · Wpo Webpagetest

Griffin Francis

·

Publicado

2019-05-17

·

Atualizado

2019-05-21

·

CVE-2019-12161

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPO WebPageTest version 19.04
Description The issue allows for Server-Side Request Forgery (SSRF) due to the ValidateURL function in www/runtest.php not properly handling octal encoding of IP addresses. For example, an IP address like 192.168 can be represented in octal as 0300.0250, which is not correctly considered by the validation.
Recommendations For WPO WebPageTest version 19.04, consider modifying the ValidateURL function to correctly handle octal encoding of IP addresses to prevent SSRF attacks. As a temporary workaround, restrict access to the www/runtest.php script until a proper fix is implemented.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-12161

Produtos afetados

Wpo Webpagetest