PT-2014-6296 · Innovative Interfaces · Innovative Interfaces Encore Discovery Solution

Publicado

2014-08-29

·

Atualizado

2018-10-09

·

CVE-2014-5127

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Innovative Interfaces Encore Discovery Solution version 4.3
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. This could potentially lead to phishing attacks.
Recommendations For version 4.3, update to a version that fixes the open redirect issue to prevent attackers from redirecting users to arbitrary web sites.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2014-5127

Produtos afetados

Innovative Interfaces Encore Discovery Solution