CVE-2018-14398

MEDIUM

Creme CRM <1.6.12 - Open Redirect

Title source: llm
STIX 2.1

Description

An issue was discovered in Creme CRM 1.6.12. The value of the cancel button uses the content of the HTTP Referer header, and could be used to trick a user into visiting a fake login page in order to steal credentials.

References (1)

Core 1
Core References

Scores

CVSS v3 6.1
EPSS 0.0068
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
cremecrm/cremecrm 1.6.12
Published Sep 07, 2018
Tracked Since Feb 18, 2026