PT-2015-3926 · Ex Libris · Ex Libris Patron Directory Services (Pds) Nyu Opensso Integration
Wang Jing
·
Published
2015-01-02
·
Updated
2015-01-05
·
CVE-2014-7294
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Ex Libris Patron Directory Services (PDS) NYU OpenSSO Integration versions 2.1 and earlier
Description
The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the
url parameter. This can be exploited by including a malicious URL in the url parameter, potentially leading to phishing attacks.Recommendations
For Ex Libris Patron Directory Services (PDS) NYU OpenSSO Integration versions 2.1 and earlier, consider restricting access to the logon page or validating the
url parameter to prevent redirects to arbitrary web sites until a fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ex Libris Patron Directory Services (Pds) Nyu Opensso Integration