S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-8982 Scanner

Detects 'Server-Side-Request-Forgery (SSRF)' vulnerability in WaveMaker Studio affects v. 6.6.

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-8982
9.6
CVSS

com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&inUrl= value, leading to disclosure of local files and SSRF.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

WaveMaker Studio is an open source app development platform that enables developers to build and deploy custom applications. It allows for seamless integrations across different systems and offers a visual drag-and-drop environment that makes app development faster and easier. The platform is known for its efficiency in creating web and mobile apps whilst providing businesses with the means to achieve their goals in the shortest possible time.

The CVE-2019-8982 vulnerability is a security flaw that was discovered in WaveMaker Studio 6.6. This vulnerability is caused by a flaw in the code that mishandles the studioService.download?method=getContent&inUrl= value. Attackers can take advantage of this flaw to gain unauthorized access and extract sensitive data from the system and may further exploit it to launch other attacks. 

Exploiting this vulnerability can lead to severe consequences such as data theft and unauthorized access to systems. This could lead to financial loss, damage to reputation, and regulatory sanctions. Since WaveMaker Studio is open source and widely used all over the world, it is imperative for developers to identify and patch this vulnerability to ensure that their digital assets remain secure at all times.

s4e.io is a platform that provides individuals and companies with advanced tools to find vulnerabilities in their digital assets. With its pro features, users can easily and quickly learn about potential vulnerabilities in their systems, including those present in WaveMaker Studio. By using this platform, businesses can ensure that their digital assets are free from security vulnerabilities, thus preventing potential attacks and protecting their reputation. 

 

REFERENCES

Solution Advice

To protect against this vulnerability, developers can take the following precautionary measures:

  • Update to WaveMaker Studio 9.x, which already has a patch for the vulnerability
  • Implement a web application firewall (WAF) to detect and block any abnormal requests
  • Regularly conduct security assessments on your system with the help of a security expert
  • Restrict access to only authorized personnel and implement strong password policies
  • Educate employees and staff about the importance of cybersecurity and how to identify and report suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-8982 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in WaveMaker Studio | S4E