CVE-2017-1000163
Phoenix Arbitrary URL Redirect
Record summary
CVE-2017-1000163 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
phoenixBrowse Hex / phoenix | GitHub Advisory | Before 1.0.6 · Fixed in 1.0.6 | affected |
| 1.1.0 to < 1.1.8 · Fixed in 1.1.8 | affected | ||
| 1.2.0 to < 1.2.3 · Fixed in 1.2.3 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMPhoenix Framework - Open RedirectCVSS 6.1
Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 contain an open redirect vulnerability, which may result in phishing or social engineering attacks.
Impact
An attacker can craft a malicious URL that redirects users to a malicious website, leading to potential phishing attacks.
Remediation
Apply the latest security patches or upgrade to a patched version of the Phoenix Framework.
Source: ProjectDiscovery