Описание
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.
Ссылки
- Third Party Advisory
- Product
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:returnfi:blitz:1.17.0:*:*:*:*:*:*:*
EPSS
Процентиль: 23%
0.00076
Низкий
6.1 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-601
Связанные уязвимости
CVSS3: 6.5
github
около 2 месяцев назад
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.
EPSS
Процентиль: 23%
0.00076
Низкий
6.1 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-601