Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/ - Third Party Advisory | |
References | () https://forums.contribs.org/index.php/topic%2C52838.0.html - |
07 Nov 2023, 02:37
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2017-07-17 13:18
Updated : 2024-11-21 03:04
NVD link : CVE-2017-1000027
Mitre link : CVE-2017-1000027
CVE.ORG link : CVE-2017-1000027
JSON object : View
Products Affected
koozali
- sme_server
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')