Record summary

CVE-2019-3912 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListVersions before 18.3.0-61806.763affected

Nuclei templates

1
ProjectDiscoveryMEDIUMLabKey Server Community Edition <18.3.0 - Open RedirectCVSS 6.1

LabKey Server Community Edition before 18.3.0-61806.763 contains an open redirect vulnerability via the /__r1/ returnURL parameter, which allows an attacker to redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.

Remediation

Upgrade LabKey Server Community Edition to version 18.3.0 or later to mitigate the vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2019cvetenableredirectlabkeyvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:labkey:labkey_server:*:*:*:*:community:*:*:*
Shodan: Server: Labkey
Shodan: http.title:"sign in: /home"
Shodan: server: labkey
FOFA: title="sign in: /home"
Google: intitle:"sign in: /home"

Source: ProjectDiscovery

References

2