There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 1
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Wgstart Wgcloud
cpe:2.3:a:wgstart:wgcloud:*:*:*:*:*:*:*:*
|
— |
<= 3.6.3
|