← All CVEs

CVE-2023-30804

medium · 4.9

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

4.9
CVSS
12.8%
EPSS (exploit prob.)
96th
EPSS percentile
2023-10-10
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-200

Affected products

VendorProductAffected versions
sangfornext-gen_application_firewall8.0.17

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-30804