There is an arbitrary file read vulnerability in the test connection function of backend database management in wgcloud v3.6.3 and before, which can be used to read any file on the victim's server.
References
| Link | Resource |
|---|---|
| https://github.com/TTTlw1024/qwe/issues/2 | Exploit Issue Tracking |
| https://github.com/tianshiyeben/wgcloud/issues/97 | Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-03-19 17:16
Updated : 2026-06-17 10:32
NVD link : CVE-2026-30403
Mitre link : CVE-2026-30403
CVE.ORG link : CVE-2026-30403
JSON object : View
Products Affected
wgstart
- wgcloud
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
