CVE-2016-10368
Opsview Monitor Pro - Open Redirect
Record summary
CVE-2016-10368 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a certain 2016 security patch) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the /login URI.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOpsview Monitor Pro - Open RedirectCVSS 6.1
Opsview Monitor Pro before 5.1.0.162300841, before 5.0.2.27475, before 4.6.4.162391051, and 4.5.x without a certain 2016 security patch contains an open redirect vulnerability. An attacker can redirect users to arbitrary web sites and conduct phishing attacks via the back parameter to the login URI.
Impact
An attacker can redirect users to malicious websites, leading to phishing attacks or the download of malware.
Remediation
Apply the latest patch or upgrade to a version that is not affected by the vulnerability.
Source: ProjectDiscovery