lorexxar.cn
http://lorexxar.cn/2017/07/20/FineCMS%20multi%20vulnerablity%20before%20v5.0.9 CVE-2017-11586
MEDIUMNuclei
FineCMS <5.0.9 - Open Redirect
Record summary
CVE-2017-11586 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMFineCMS <5.0.9 - Open RedirectCVSS 6.1
FineCMS 5.0.9 contains an open redirect vulnerability via the url parameter in a sync action. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Upgrade to FineCMS version 5.0.9 or later to fix the open redirect vulnerability.
WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2017redirectfinecmsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:finecms:finecms:*:*:*:*:*:*:*:*
http://lorexxar.cn/2017/07/20/FineCMS%20multi%20vulnerablity%20before%20v5.0.9/#URL-Redirector-Abuse https://nvd.nist.gov/vuln/detail/CVE-2017-11586
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-11586