mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
1.2 KiB
1.2 KiB
CVE-2024-22196
Description
Nginx-UI is an online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. This issue may lead to information disclosure. By using DefaultQuery
, the "desc"
and "id"
values are used as default values if the query parameters are not set. Thus, the order
and sort_by
query parameter are user-controlled and are being appended to the order
variable without any sanitization. This issue has been patched in version 2.0.0.beta.9.
POC
Reference
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h374-mm57-879c
- https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-h374-mm57-879c