Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cc4-gwfx-gr3r

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted characters in the domain name of a subdomain.

Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted characters in the domain name of a subdomain.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-20

Связанные уязвимости

nvd
около 14 лет назад

Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted characters in the domain name of a subdomain.

EPSS

Процентиль: 45%
0.00224
Низкий

Дефекты

CWE-20