CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.6. It affects Java. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 25.6% probability of exploitation in the next 30 days.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
External Security References
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2019-8982
Severity
CRITICAL
CVSS
9.6
EPSS
25.56%
Java
Original NVD Description
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.