Описание
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in Release 24.2020.20608.0
Ссылки
- Third Party Advisory
- Third Party Advisory
- ProductVendor Advisory
- Third Party Advisory
- Third Party Advisory
- ProductVendor Advisory
Уязвимые конфигурации
EPSS
5.2 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
Связанные уязвимости
** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. NOTE: the vendor does not recognize this issue and will not patch it.
EPSS
5.2 Medium
CVSS3
4.3 Medium
CVSS2