Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mg3-xw6r-4frw

Опубликовано: 02 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

EPSS

Процентиль: 7%
0.00171
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 дня назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

CVSS3: 4.3
redhat
7 дней назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

CVSS3: 4.3
nvd
4 дня назад

reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.

CVSS3: 4.3
debian
4 дня назад

reset_password.html parses query string parameters and uses the 'url' ...

EPSS

Процентиль: 7%
0.00171
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601