PT-2013-1791 · Jforum · Jforum
Published
2013-09-23
·
Updated
2013-09-24
·
CVE-2012-5338
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JForum version 2.1.9
Description
A security issue allows remote attackers to redirect users to arbitrary web sites, potentially leading to phishing attacks. This is achieved by manipulating a URL in the
returnPath parameter within a validateLogin action to jforum.page.Recommendations
For JForum version 2.1.9, as a temporary workaround, consider restricting access to the
validateLogin action or validating the returnPath parameter to prevent redirects to unauthorized sites.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jforum