PT-2021-15827 · Unknown · Acymailing

Viktor Markopoulos

·

Published

2021-05-17

·

Updated

2021-05-25

·

CVE-2021-24288

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions AcyMailing (affected versions not specified)
Description The issue arises when subscribing using AcyMailing, where the redirect parameter is not properly sanitized. An attacker can exploit this by turning a POST request into a GET request, allowing them to craft a link with a potentially malicious landing page that can be sent to a victim.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-24288

Affected Products

Acymailing