PT-2019-7083 · Posh · Posh
Anthony Baube
+1
·
Published
2019-11-22
·
Updated
2019-12-03
·
CVE-2014-2213
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
POSH versions 3.0 through 3.2.1
Description
The issue concerns a problem in the password reset functionality that allows remote attackers to redirect users to arbitrary web sites, potentially leading to phishing attacks. This is achieved by manipulating a URL in the
redirect parameter to the /portal/scr sendmd5.php API endpoint.Recommendations
For POSH versions 3.0 through 3.2.1, as a temporary workaround, consider restricting access to the password reset functionality until a fix is available. Avoid using the
redirect parameter in the /portal/scr sendmd5.php API endpoint to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Posh