Remote Application Exposure in Parallels RAS
CVE-2020-35710
5.3MEDIUM
What is CVE-2020-35710?
The Parallels Remote Application Server 18 exposes the intranet IP address during the login process. When a user attempts to log in, even with no credentials provided, the login form leaks the internal IP address back to the attacker's client. This occurs as the system processes the initial request and subsequently sends a POST request containing the intranet IP in the 'host' value to a different endpoint. This vulnerability can enable remote attackers to gather sensitive network information, which may be exploited for further attacks.