Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56m9-2h59-x23m

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.

EPSS

Процентиль: 47%
0.00242
Низкий

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
nvd
около 4 лет назад

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers.

EPSS

Процентиль: 47%
0.00242
Низкий

Дефекты

CWE-601