PT-2014-6296 · Innovative Interfaces · Innovative Interfaces Encore Discovery Solution

Published

2014-08-29

·

Updated

2018-10-09

·

CVE-2014-5127

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Innovative Interfaces Encore Discovery Solution version 4.3
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter. This could potentially lead to phishing attacks.
Recommendations For version 4.3, update to a version that fixes the open redirect issue to prevent attackers from redirecting users to arbitrary web sites.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-5127

Affected Products

Innovative Interfaces Encore Discovery Solution