CVE-2015-7823
Kentico CMS 8.2 - Open Redirect
Record summary
CVE-2015-7823 has a selected CVSS score of 5.8; EIP currently links 1 Nuclei template.
Description
Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMKentico CMS 8.2 - Open RedirectCVSS 5.8
Kentico CMS 8.2 contains an open redirect vulnerability via GetDocLink.ashx with link variable. An attacker can construct a URL within the application that causes a redirection to an arbitrary external domain.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.
Remediation
Apply the latest security patches or upgrade to a newer version of Kentico CMS.
Source: ProjectDiscovery