Record summary

CVE-2015-4668 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBXceedium Xsuite - Multiple VulnerabilitiesExploitDB exploitby modzeroNot analyzed1 file

linked to 6 vulnerabilities

ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMXsuite <=2.4.4.5 - Open RedirectCVSS 6.1

Xsuite 2.4.4.5 and prior contains an open redirect vulnerability, which can allow a remote attacker to redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the redirurl parameter.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.

Remediation

Upgrade Xsuite to a version higher than 2.4.4.5 to mitigate the open redirect vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2015cveredirectxsuitexceediumedbvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:xceedium:xsuite:2.3.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

5