Record summary

CVE-2015-7823 has a selected CVSS score of 5.8; EIP currently links 1 Nuclei template.

Description

Open redirect vulnerability in CMSPages/GetDocLink.ashx in Kentico CMS 8.2 through 8.2.41 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the link parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMKentico CMS 8.2 - Open RedirectCVSS 5.8

Kentico CMS 8.2 contains an open redirect vulnerability via GetDocLink.ashx with link variable. An attacker can construct a URL within the application that causes a redirection to an arbitrary external domain.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the installation of malware.

Remediation

Apply the latest security patches or upgrade to a newer version of Kentico CMS.

Authors0x_Akoko
Template tagscve2015cvekenticoredirectpacketstormvuln
CVSS vector: CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:N
CPE: cpe:2.3:a:kentico:kentico_cms:8.2:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:kentico:kentico_cms"
Shodan: http.title:"kentico database setup"
FOFA: title="kentico database setup"
Google: intitle:"kentico database setup"

Source: ProjectDiscovery

References

2