CVE-2018-12300
Seagate NAS OS 4.3.15.1 - Open Redirect
Record summary
CVE-2018-12300 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSeagate NAS OS 4.3.15.1 - Open RedirectCVSS 6.1
Seagate NAS OS 4.3.15.1 contains an open redirect vulnerability in echo-server.html, which can allow an attacker to disclose information in the referer header via the state URL parameter.
Impact
Successful exploitation of this vulnerability could lead to user redirection to malicious websites, potentially resulting in the theft of sensitive information or the installation of malware.
Remediation
Apply the latest security patches or updates provided by Seagate to fix the open redirect vulnerability in NAS OS 4.3.15.1.
Source: ProjectDiscovery