Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fpgv-9v95-hrgv

Опубликовано: 09 дек. 2021
Источник: github
Github: Не прошло ревью

Описание

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.1
nvd
около 4 лет назад

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy via crafted GET parameters in requests to error handlers

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-601