CVE-2020-21998
HomeAutomation 3.3.2 - Open Redirect
Record summary
CVE-2020-21998 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMHomeAutomation 3.3.2 - Open RedirectCVSS 6.1
HomeAutomation 3.3.2 contains a redirect vulnerability caused by improper verification of the 'redirect' GET parameter in 'api.php', letting attackers redirect users to arbitrary websites, exploit requires user interaction with a crafted link.
Impact
Attackers can redirect users to malicious external websites through crafted links, potentially facilitating phishing attacks or malware distribution.
Remediation
Upgrade to HomeAutomation version 3.3.3 or later, or apply vendor-provided security patches.
Source: ProjectDiscovery