URL Redirection to Untrusted Site ('Open Redirect')
CVE-2017-20164
Summary
A vulnerability was found in Symbiote Seed 6.0.2. It has been classified as critical. Affected is the function "onBeforeSecurityLogin" of the file "code/extensions/SecurityLoginExtension.php" of the component "Login". The manipulation of the argument URL leads to open redirect. It is possible to launch the attack remotely. Upgrading to version 6.0.3 is able to address this issue. It is recommended to upgrade the affected component. VDB-217626 is the identifier assigned to this vulnerability.
- LOW
- NETWORK
- LOW
- CHANGED
- REQUIRED
- NONE
- LOW
- NONE
CWE-601 - Open Redirect
An open redirect attack employs a URL parameter, HTML refresh tags, or a DOM based location change to exploit the trust of a vulnerable domain to direct the users to a malicious website. The attack could lead to higher severity vulnerabilities such as unauthorized access control, account takeover, XSS, and more.
References
Advisory Timeline
- Published