The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
- https://aws.amazon.com/marketplace/pp/prodview-uujwjffddxzp4
No PoCs found on GitHub currently.