PT-2022-17525 · Unknown · Cert/Cc Vince

Jlleitschuh

+1

·

Published

2022-08-16

·

Updated

2022-11-16

·

CVE-2022-25799

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CERT/CC VINCE versions prior to 1.50.0
Description An open redirect issue exists, allowing an attacker to send a specially crafted URL link that, when clicked by an authenticated user, could redirect the user's browser to a malicious site impersonating a legitimate website. This could potentially lead to the acquisition of sensitive information, such as user credentials.
Recommendations For versions prior to 1.50.0, update to version 1.50.0 or later to resolve the issue. As a temporary workaround, consider avoiding clicking on links from untrusted sources and verifying the authenticity of websites before entering sensitive information. Restrict access to the software until the update is applied to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-25799

Affected Products

Cert/Cc Vince