Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqxm-c9wh-542c

Опубликовано: 27 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

EPSS

Процентиль: 55%
0.0033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.3
nvd
больше 1 года назад

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

EPSS

Процентиль: 55%
0.0033
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-601