CVE-2019-3912
LabKey Server Community Edition <18.3.0 - Open Redirect
Record summary
CVE-2019-3912 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
LabKey Server Community EditionBrowse Tenable / LabKey Server Community Edition | CVE List | Versions before 18.3.0-61806.763 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMLabKey Server Community Edition <18.3.0 - Open RedirectCVSS 6.1
LabKey Server Community Edition before 18.3.0-61806.763 contains an open redirect vulnerability via the /__r1/ returnURL parameter, which allows an attacker to redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
Remediation
Upgrade LabKey Server Community Edition to version 18.3.0 or later to mitigate the vulnerability.
Source: ProjectDiscovery