Record summary

CVE-2017-1000163 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 1.0.6 · Fixed in 1.0.6affected
1.1.0 to < 1.1.8 · Fixed in 1.1.8affected
1.2.0 to < 1.2.3 · Fixed in 1.2.3affected

Nuclei templates

1
ProjectDiscoveryMEDIUMPhoenix Framework - Open RedirectCVSS 6.1

Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 contain an open redirect vulnerability, which may result in phishing or social engineering attacks.

Impact

An attacker can craft a malicious URL that redirects users to a malicious website, leading to potential phishing attacks.

Remediation

Apply the latest security patches or upgrade to a patched version of the Phoenix Framework.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2017redirectphoenixphoenixframeworkvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:phoenixframework:phoenix:1.0.0:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3