PT-2022-17525 · Unknown · Cert/Cc Vince
Jlleitschuh
+1
·
Published
2022-08-16
·
Updated
2022-11-16
·
CVE-2022-25799
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CERT/CC VINCE versions prior to 1.50.0
Description
An open redirect issue exists, allowing an attacker to send a specially crafted URL link that, when clicked by an authenticated user, could redirect the user's browser to a malicious site impersonating a legitimate website. This could potentially lead to the acquisition of sensitive information, such as user credentials.
Recommendations
For versions prior to 1.50.0, update to version 1.50.0 or later to resolve the issue. As a temporary workaround, consider avoiding clicking on links from untrusted sources and verifying the authenticity of websites before entering sensitive information. Restrict access to the software until the update is applied to minimize the risk of exploitation.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cert/Cc Vince