PT-2015-7632 · Kentico · Kentico Cms

Published

2015-10-21

·

Updated

2015-10-23

·

CVE-2015-7823

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Kentico CMS versions 8.2 through 8.2.41
Description The issue allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter in the CMSPages/GetDocLink.ashx endpoint.
Recommendations For Kentico CMS versions 8.2 through 8.2.41, update to a version that contains a fix for this issue to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-7823

Affected Products

Kentico Cms