Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g96r-v5qq-9qch

Опубликовано: 15 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.7

Описание

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.

This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

EPSS

Процентиль: 44%
0.00221
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 4.7
nvd
больше 1 года назад

A vulnerability in the web-based management interface of Cisco Crosswork Network Services Orchestrator (NSO) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of a parameter in an HTTP request. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A successful exploit could allow the attacker to redirect a user to a malicious website.

CVSS3: 4.7
fstec
больше 1 года назад

Уязвимость веб-интерфейса программного средства автоматизации Cisco Crosswork Network Services Orchestrator, позволяющая нарушителю проводить фишинг-атаки

EPSS

Процентиль: 44%
0.00221
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-601