ABB Cylon Aspect 3.08.01 jsonProxy.php Unauthenticated Project Download

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    ABB Cylon Aspect version 3.08.01 is vulnerable to an unauthorized project file disclosure in jsonProxy.php. An unauthenticated remote attacker can issue a GET request abusing the DownloadProject servlet to download sensitive project files. The jsonProxy.php script bypasses authentication by proxying requests to localhost (AspectFT Automation Application Server), granting remote attackers unauthorized access to internal Java servlets. This exposes potentially sensitive project data and configuration details without requiring authentication.

    Continue reading...
     

Share This Page

Loading...