PT-2021-19704 · Unknown · Wfilter Icf
Driver Tom
·
Published
2021-04-15
·
Updated
2021-04-20
·
CVE-2021-3243
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Wfilter ICF version 5.0.117
Description:
The issue allows an attacker in the same LAN to inject a payload into the system's logs by crafting a packet with a malicious
User-Agent header. This can lead to a takeover of the system through its plugin-running function.Recommendations:
For Wfilter ICF version 5.0.117, consider disabling the plugin-running function as a temporary workaround until a patch is available. Restrict access to the system's logs to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wfilter Icf