Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-3027

Опубликовано: 31 мар. 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:primekey:ejbca:*:*:*:*:enterprise:*:*:*
Версия от 8.0 (включая) до 9.1 (исключая)

EPSS

Процентиль: 12%
0.00041
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
github
10 месяцев назад

The vulnerability exists in the EJBCA service, version 8.0 Enterprise. By making a small change to the PATH of the URL associated with the service, the server fails to find the requested file and redirects to an external page. This vulnerability could allow users to be redirected to potentially malicious external sites, which can be exploited for phishing or other social engineering attacks.

EPSS

Процентиль: 12%
0.00041
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601