Логотип exploitDog
bind:CVE-2024-53264
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-53264

Количество 2

Количество 2

nvd логотип

CVE-2024-53264

около 1 года назад

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowing attackers to redirect authenticated users to arbitrary external URLs via the "next" parameter. The loading endpoint accepts and uses an unvalidated "next" parameter for redirects. Ex. visiting: `/loading?next=https://google.com` while authenticated will cause the page will redirect to google.com. This vulnerability could be used in phishing attacks by redirecting users from a legitimate application URL to malicious sites. This issue has been addressed in version 1.5.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

EPSS: Низкий
github логотип

GHSA-q9rr-h3hx-m87g

около 1 года назад

BunkerWeb has Open Redirect Vulnerability in Loading Page

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-53264

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowing attackers to redirect authenticated users to arbitrary external URLs via the "next" parameter. The loading endpoint accepts and uses an unvalidated "next" parameter for redirects. Ex. visiting: `/loading?next=https://google.com` while authenticated will cause the page will redirect to google.com. This vulnerability could be used in phishing attacks by redirecting users from a legitimate application URL to malicious sites. This issue has been addressed in version 1.5.11. Users are advised to upgrade. There are no known workarounds for this vulnerability.

0%
Низкий
около 1 года назад
github логотип
GHSA-q9rr-h3hx-m87g

BunkerWeb has Open Redirect Vulnerability in Loading Page

0%
Низкий
около 1 года назад

Уязвимостей на страницу