Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5j8m-6w2f-56vm

Опубликовано: 08 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 4.7

Описание

The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.

The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.

EPSS

Процентиль: 26%
0.00093
Низкий

5.1 Medium

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
nvd
больше 1 года назад

The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.

CVSS3: 4.7
fstec
больше 1 года назад

Уязвимость веб-сервера микропрограммного обеспечения программируемых логических контроллеров SIMATICS7-1500 и S7-1200 CPU family, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 26%
0.00093
Низкий

5.1 Medium

CVSS4

4.7 Medium

CVSS3

Дефекты

CWE-601