HTTP Request Field Handling Vulnerability in Embedthis GoAhead and Appweb
CVE-2018-15504
7.5HIGH
What is CVE-2018-15504?
An issue has been identified in the handling of specific HTTP request fields within Embedthis GoAhead and Appweb. This vulnerability can result in a NULL pointer dereference, potentially causing server crashes when certain date fields, such as If-Modified-Since or If-Unmodified-Since, are manipulated incorrectly, especially with values representing months greater than 11. The affected versions prior to 4.0.1 for GoAhead and 7.0.2 for Appweb are particularly susceptible to this issue, highlighting a need for immediate patches to prevent service disruptions.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved