First published: Wed Aug 12 2020(Updated: )
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator privileges through SQL injection of the apikey parameter in fw.login.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Proxy | =4.30.000000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-17506 is considered critical due to the potential for remote attackers to gain administrative access.
To fix CVE-2020-17506, upgrade Artica Web Proxy to the latest version that addresses this vulnerability.
CVE-2020-17506 is an SQL injection vulnerability that allows privilege escalation through the apikey parameter.
Artica Web Proxy version 4.30.000000 is specifically affected by CVE-2020-17506.
Yes, CVE-2020-17506 can be exploited by remote attackers without needing physical access to the system.