Описание
Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0.
Ссылки
- Patch
- Issue Tracking
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.69.0 (исключая)
cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:*
EPSS
Процентиль: 13%
0.00043
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-601
EPSS
Процентиль: 13%
0.00043
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-601