github.com
https://github.com/Submitty/Submitty/issues/5265 CVE-2020-13121
MEDIUMNuclei
Submitty <= 20.04.01 - Open Redirect
Record summary
CVE-2020-13121 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
Submitty through 20.04.01 has an open redirect via authentication/login?old= during an invalid login attempt.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMSubmitty <= 20.04.01 - Open RedirectCVSS 6.1
Submitty through 20.04.01 contains an open redirect vulnerability via authentication/login?old= during an invalid login attempt. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Upgrade to Submitty version 20.04.01 or later to fix the open redirect vulnerability.
WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2020redirectsubmittyoosrcosvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:rcos:submitty:*:*:*:*:*:*:*:*
https://github.com/Submitty/Submitty/issues/5265 https://nvd.nist.gov/vuln/detail/CVE-2020-13121 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-13121