Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39956
Published: February 9, 2023
OWASP ModSecurity Core Rule Set (CRS)
OWASP
Description
The vulnerability allows a remote attacker to bypass filtration rules.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set.