MEDIUM🇵🇱 Wersja polska

CVE-2023-30804

CVSS 4.9v3.1pub. 2023-10-10upd. 2025-11-28

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
  • Sangfor Next Gen Application Firewall

    APP
    Sangfor
    8.0.17
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassFirewallVPN
CWE
References

Related vulnerabilities

CVE-2023-30803CRITICAL9.8PL ✓same product

Sangfor NGAF — ominięcie uwierzytelnienia przez nagłówek HTTP

CVE-2023-30805CRITICAL9.8PL ✓same product

Sangfor NGAF — nieuwierzytelniony command injection w /LogInOut.php

CVE-2023-30806CRITICAL9.8PL ✓same product

Sangfor NGAF — nieuwierzytelniony command injection przez cookie PHPSESSID

CVE-2023-30802MEDIUM5.3same product

The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnera...

CVE-2026-1324HIGH7.4same vendor

A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected b...