ZeroHour

CVE-2020-17506

PoC ×3
CVSS 3.1
9.8 critical
EPSS
94%p100
Published
()
Modified
Description

Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.

Vendors
articatech
Products
web proxy
Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.