A spoofing attack in ujcms v.8.0.2 allows a remote...
Critical severity
Unreviewed
Published
Jan 12, 2024
to the GitHub Advisory Database
•
Updated Jan 27, 2024
Description
Published by the National Vulnerability Database
Jan 11, 2024
Published to the GitHub Advisory Database
Jan 12, 2024
Last updated
Jan 27, 2024
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.
References