CVE-2015-4668
Xceedium Xsuite - Multiple Vulnerabilities
Record summary
CVE-2015-4668 has a selected CVSS score of 6.1 (medium); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBXceedium Xsuite - Multiple VulnerabilitiesExploitDB exploitby modzeroNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMXsuite <=2.4.4.5 - Open RedirectCVSS 6.1
Xsuite 2.4.4.5 and prior contains an open redirect vulnerability, which can allow a remote attacker to redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the redirurl parameter.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.
Remediation
Upgrade Xsuite to a version higher than 2.4.4.5 to mitigate the open redirect vulnerability.
Source: ProjectDiscovery