CVE-2017-1000027

Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:koozali:sme_server:8.0:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:9.2:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 03:04

Type Values Removed Values Added
References () https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/ - Third Party Advisory () https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/ - Third Party Advisory
References () https://forums.contribs.org/index.php/topic%2C52838.0.html - () https://forums.contribs.org/index.php/topic%2C52838.0.html -

07 Nov 2023, 02:37

Type Values Removed Values Added
References
  • {'url': 'https://forums.contribs.org/index.php/topic,52838.0.html', 'name': 'https://forums.contribs.org/index.php/topic,52838.0.html', 'tags': ['Third Party Advisory'], 'refsource': 'MISC'}
  • () https://forums.contribs.org/index.php/topic%2C52838.0.html -

Information

Published : 2017-07-17 13:18

Updated : 2024-11-21 03:04


NVD link : CVE-2017-1000027

Mitre link : CVE-2017-1000027

CVE.ORG link : CVE-2017-1000027


JSON object : View

Products Affected

koozali

  • sme_server
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')