Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-grp5-2x24-q4vj

Опубликовано: 15 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

EPSS

Процентиль: 39%
0.00174
Низкий

8.2 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 8.2
nvd
около 2 лет назад

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

CVSS3: 9.3
fstec
около 2 лет назад

Уязвимость программных средств создания панелей управления для систем управления электроэнергией EcoStruxure PowerSCADA Operation (PSO) - Advanced Reporting and Dashboards Module, EcoStruxure PowerOperation (EPO) - Advanced Reporting and Dashboards Module и программного обеспечения энергомониторинга EcoStruxure Power Monitoring Expert, связанная с переадресацией URL на ненадежный сайт, позволяющая нарушителю перенаправить пользователя на произвольный URL-адрес

EPSS

Процентиль: 39%
0.00174
Низкий

8.2 High

CVSS3

Дефекты

CWE-601