PT-2017-10737 · Koozali Foundation · Sme Server
Published
2017-07-13
·
Updated
2017-07-21
·
CVE-2017-1000027
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Koozali Foundation SME Server versions 8.x through 10.x
Description
The issue concerns an open URL redirect vulnerability in the user web login function, which can result in unauthorized account access.
Recommendations
For versions 8.x through 10.x, update the user web login function to prevent open URL redirects, ensuring that login requests are properly validated to prevent unauthorized access.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sme Server