PT-2017-12121 · Dayrui · Finecms

Lorexxar

·

Publicado

2017-07-24

·

Atualizado

2017-07-28

·

CVE-2017-11586

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions dayrui FineCms version 5.0.9
Description The issue concerns URL Redirector Abuse via the url parameter in a sync action, related to the controllers/Weixin.php file.
Recommendations For dayrui FineCms version 5.0.9, consider restricting access to the url parameter in the sync action to minimize the risk of exploitation. Avoid using the url parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-11586

Produtos afetados

Finecms