Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3f9q-jjqq-4g32

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not validated.

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not validated.

EPSS

Процентиль: 41%
0.00192
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
больше 8 лет назад

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not validated.

CVSS3: 6.1
debian
больше 8 лет назад

An open redirect vulnerability is present in Piwigo 2.9 and probably p ...

EPSS

Процентиль: 41%
0.00192
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601