PT-2017-12121 · Dayrui · Finecms
Lorexxar
·
Published
2017-07-24
·
Updated
2017-07-28
·
CVE-2017-11586
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
dayrui FineCms version 5.0.9
Description
The issue concerns URL Redirector Abuse via the
url parameter in a sync action, related to the controllers/Weixin.php file.Recommendations
For dayrui FineCms version 5.0.9, consider restricting access to the
url parameter in the sync action to minimize the risk of exploitation. Avoid using the url parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Finecms