CVE-2023-30802: Sangfor Next-Gen Application Firewall Source Code Disclosure
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Sangfor Next-Gen Application Firewall?
The vulnerability ID for Sangfor Next-Gen Application Firewall is CVE-2023-30802.
What is the severity rating of CVE-2023-30802?
CVE-2023-30802 has a severity rating of 5.3, which is medium.
How does CVE-2023-30802 affect Sangfor Next-Gen Application Firewall version NGAF8.0.17?
CVE-2023-30802 affects Sangfor Next-Gen Application Firewall version NGAF8.0.17 by allowing a remote and unauthenticated attacker to obtain PHP source code through an HTTP request with an invalid Content-Length field.
How can I fix the source code disclosure vulnerability in Sangfor Next-Gen Application Firewall?
To fix the source code disclosure vulnerability in Sangfor Next-Gen Application Firewall, it is recommended to update to a version that is not affected by the vulnerability or apply any patches or security updates provided by the vendor.
Are there any references or additional information about CVE-2023-30802?
Yes, you can find more information about CVE-2023-30802 in the following references: [link1], [link2], [link3].