CVE-2016-5304

MEDIUM

Symantec Endpoint Protection Manager < 12.1.6 - Open Redirect

Title source: rule

Description

Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Exploits (1)

exploitdb WORKING POC VERIFIED
by hyp3rlinx · textwebappsphp
https://www.exploit-db.com/exploits/40041

Scores

CVSS v3 6.8
EPSS 0.0715
EPSS Percentile 91.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Classification

Status draft

Affected Products (1)

symantec/endpoint_protection_manager < 12.1.6

Timeline

Published Jun 30, 2016
Tracked Since Feb 18, 2026