Описание
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
Ссылки
- Vendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 3.1.0 (включая) до 3.1.8 (включая)
cpe:2.3:a:appleple:a-blog_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00255
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 4.7
github
почти 2 года назад
URL spoofing vulnerability exists in a-blog cms Ver.3.1.0 to Ver.3.1.8. If an attacker sends a specially crafted request, the administrator of the product may be forced to access an arbitrary website when clicking a link in the audit log.
EPSS
Процентиль: 49%
0.00255
Низкий
4.7 Medium
CVSS3
Дефекты
CWE-601