The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NSangfor Next Gen Application Firewall
APPSangfor8.0.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassFirewall
References
Related vulnerabilities
CVE-2023-30803CRITICAL9.8PL ✓same product
Sangfor NGAF — ominięcie uwierzytelnienia przez nagłówek HTTP
CVE-2023-30805CRITICAL9.8PL ✓same product
Sangfor NGAF — nieuwierzytelniony command injection w /LogInOut.php
CVE-2023-30806CRITICAL9.8PL ✓same product
Sangfor NGAF — nieuwierzytelniony command injection przez cookie PHPSESSID
CVE-2023-30804MEDIUM4.9same product
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure...
CVE-2026-1324HIGH7.4same vendor
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...