Record summary

CVE-2017-14524 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Multiple open redirect vulnerabilities in OpenText Documentum Administrator 7.2.0180.0055 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a (1) URL in the startat parameter to xda/help/en/default.htm or (2) /%09/ (slash encoded horizontal tab slash) followed by a domain in the redirectUrl parameter to xda/component/virtuallinkconnect.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOpenText Documentum Administrator 7.2.0180.0055 - Open RedirectCVSS 6.1

OpenText Documentum Administrator 7.2.0180.0055 is susceptible to multiple open redirect vulnerabilities. An attacker can redirect a user to a malicious site and potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the download of malware.

Remediation

Apply the latest security patches or upgrade to a patched version of OpenText Documentum Administrator.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2017cveredirectopentextseclistsvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:opentext:documentum_administrator:7.2.0180.0055:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3