PT-2017-10737 · Koozali Foundation · Sme Server
Publicado
2017-07-13
·
Atualizado
2017-07-21
·
CVE-2017-1000027
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Koozali Foundation SME Server versions 8.x through 10.x
Description
The issue concerns an open URL redirect vulnerability in the user web login function, which can result in unauthorized account access.
Recommendations
For versions 8.x through 10.x, update the user web login function to prevent open URL redirects, ensuring that login requests are properly validated to prevent unauthorized access.
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sme Server