CVE-2020-24550
EpiServer Find <13.2.7 - Open Redirect
Record summary
CVE-2020-24550 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMEpiServer Find <13.2.7 - Open RedirectCVSS 6.1
EpiServer Find before 13.2.7 contains an open redirect vulnerability via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Upgrade to EpiServer Find version 13.2.7 or later to fix the open redirect vulnerability.
Source: ProjectDiscovery