CVE-2015-3898

MEDIUM

Bonita BPM Portal <6.5.3 - Open Redirect

Title source: llm
STIX 2.1

Description

Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/loginservice.

Exploits (1)

exploitdb WRITEUP VERIFIED
by High-Tech Bridge SA · textwebappsjsp
https://www.exploit-db.com/exploits/37260

References (3)

Core 3
Core References
Exploit, Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535733/100/0/threaded
Exploit, Third Party Advisory x_refsource_misc
https://www.htbridge.com/advisory/HTB23259

Scores

CVSS v3 6.1
EPSS 0.0341
EPSS Percentile 87.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
bonitasoft/bonita_bpm_portal < 6.5.3
Published Feb 28, 2018
Tracked Since Feb 18, 2026