Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-24406

Опубликовано: 06 июл. 2021
Источник: nvd
CVSS3: 6.1
CVSS2: 5.8
EPSS Низкий

Описание

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gvectors:wpforo_forum:*:*:*:*:*:wordpress:*:*
Версия до 1.9.7 (исключая)

EPSS

Процентиль: 92%
0.08523
Низкий

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601

Связанные уязвимости

github
больше 3 лет назад

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

EPSS

Процентиль: 92%
0.08523
Низкий

6.1 Medium

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-601