PT-2019-7083 · Posh · Posh
Anthony Baube
+1
·
Publicado
2019-11-22
·
Atualizado
2019-12-03
·
CVE-2014-2213
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
POSH versions 3.0 through 3.2.1
Description
The issue concerns a problem in the password reset functionality that allows remote attackers to redirect users to arbitrary web sites, potentially leading to phishing attacks. This is achieved by manipulating a URL in the
redirect parameter to the /portal/scr sendmd5.php API endpoint.Recommendations
For POSH versions 3.0 through 3.2.1, as a temporary workaround, consider restricting access to the password reset functionality until a fix is available. Avoid using the
redirect parameter in the /portal/scr sendmd5.php API endpoint to minimize the risk of exploitation.Exploit
Correção
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Posh