A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
Link | Tags |
---|---|
https://www.ujcms.com/ | product |
https://github.com/ujcms/ujcms | product |
https://github.com/ujcms/ujcms/issues/7 | third party advisory issue tracking exploit |