Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hrfh-hw79-vvhm

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a trustworthy domain but end up at an unexpected service later on. This vulnerability can be used to prepare and enhance phishing attacks.

An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a trustworthy domain but end up at an unexpected service later on. This vulnerability can be used to prepare and enhance phishing attacks.

EPSS

Процентиль: 42%
0.00201
Низкий

7.4 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.4
nvd
около 9 лет назад

An issue was discovered in Open-Xchange OX AppSuite before 7.8.0-rev27. The "defer" servlet offers to redirect a client to a specified URL. Since some checks were missing, arbitrary URLs could be provided as redirection target. Users can be tricked to follow a link to a trustworthy domain but end up at an unexpected service later on. This vulnerability can be used to prepare and enhance phishing attacks.

EPSS

Процентиль: 42%
0.00201
Низкий

7.4 High

CVSS3

Дефекты

CWE-601