DALIM SOFTWARE ES Core 5.0 build...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Description A server-side request forgery (SSRF) vulnerability exists in the DALIM Web Service management interface within the XUI servlet functionality. The DALIM web services are a set of tools used by the different DALIM SOFTWARE applications: TWIST, MISTRAL and ES. It provides file sharing capabilities, JDF devices, JDF controller, and job spooling management. The application parses user supplied data in the GET parameter 'screen' to construct a page request to the service. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make a HTTP request to an arbitrary destination host. This can be used by an external attacker for example to bypass firewalls and initiate a service and network enumeration on the internal network through the affected application. ### Vendor Dalim Software GmbH - https://www.dalim.com ### Affected Version * ES/ESPRiT 5.0 (build 7184.1) * (build 7163.2) * (build 7163.0) * (build...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息