Description
The route lookup process in beego through 1.12.4 and 2.x through 2.0.2 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
Remediation
References
Related Vulnerabilities
ReviveAdserver Deserialization of Untrusted Data Vulnerability (CVE-2017-5830)
Dotclear Other Vulnerability (CVE-2005-3963)
Drupal Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3231)
WordPress Plugin Vuukle Comments, Reactions, Share Bar, Revenue Cross-Site Request Forgery (3.4.31)