CVE-2017-14524
OpenText Documentum Administrator 7.2.0180.0055 - Open Redirect
Record summary
CVE-2017-14524 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMOpenText Documentum Administrator 7.2.0180.0055 - Open RedirectCVSS 6.1
OpenText Documentum Administrator 7.2.0180.0055 is susceptible to multiple open redirect vulnerabilities. An attacker can redirect a user to a malicious site and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.
Remediation
Apply the latest security patches or upgrade to a patched version of OpenText Documentum Administrator.
Source: ProjectDiscovery