PT-2026-107335 · Adm · Adm
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ADM versions 4.1.0 through 4.3.3.RWC1
ADM versions 5.0.0 through 5.1.4.RL21
Description
An HTTP header injection issue in the 'start-page-loader.cgi' endpoint allows an unauthenticated remote attacker to read arbitrary files on the host system. By sending a crafted HTTP request with injected headers via the
state parameter, the attacker can leverage the web server's X-Sendfile mechanism to retrieve sensitive files. X-Sendfile is a feature that allows a web application to tell the web server to serve a specific file from the disk instead of the application generating the content.Recommendations
Update ADM versions 4.1.0 through 4.3.3.RWC1 to a newer version.
Update ADM versions 5.0.0 through 5.1.4.RL21 to a newer version.
Restrict access to the 'start-page-loader.cgi' endpoint to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adm