Unauthenticated File Read Vulnerability in Weaver e-Bridge by Weaver
CVE-2020-37278
8.7HIGH
What is CVE-2020-37278?
Weaver e-Bridge contains a vulnerability that allows remote attackers to read arbitrary files on the host system. By supplying a file URL to the downloadUrl parameter of the saveYZJFile endpoint, attackers can exploit this flaw to access sensitive information, including system files like /etc/passwd, as well as configuration and credential files. Additionally, the endpoint's support for HTTP/HTTPS URLs opens the door for potential server-side request forgery attacks against internal network resources, posing a significant security risk to affected systems.
Affected Version(s)
e-Bridge *
