PT-2017-16158 · Cisco · Cisco Registered Envelope Service

Publicado

2017-04-07

·

Atualizado

2017-04-14

·

CVE-2017-3889

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cisco Registered Envelope Service version 5.1.0-015
Description A vulnerability in the web interface could allow an unauthenticated, remote attacker to redirect a user to an undesired web page, also known as an Open Redirect. This issue affects the Cisco Registered Envelope cloud-based service.
Recommendations For version 5.1.0-015, update to a version that includes the fix for this issue to prevent unauthorized redirects.

Correção

Open Redirect

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-3889

Produtos afetados

Cisco Registered Envelope Service