Record summary

CVE-2020-23015 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An open redirect issue was discovered in OPNsense through 20.1.5. The redirect parameter "url" in login page was not filtered and can redirect user to any website.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMOPNsense <=20.1.5 - Open RedirectCVSS 6.1

OPNsense through 20.1.5 contains an open redirect vulnerability via the url redirect parameter in the login page, which is not filtered. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

Successful exploitation of this vulnerability could allow an attacker to redirect users to malicious websites, leading to phishing attacks or the disclosure of sensitive information.

Remediation

Upgrade OPNsense to a version higher than 20.1.5 to mitigate the vulnerability.

WeaknessesCWE-601
Authors0x_Akoko
Template tagscve2020cveredirectopnsensevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*
Shodan: http.title:"opnsense"
FOFA: title="opnsense"
Google: intitle:"opnsense"

Source: ProjectDiscovery

References

2