Record summary

CVE-2020-24550 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMEpiServer Find <13.2.7 - Open RedirectCVSS 6.1

EpiServer Find before 13.2.7 contains an open redirect vulnerability via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL. An attacker can redirect a user to a malicious site and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.

Remediation

Upgrade to EpiServer Find version 13.2.7 or later to fix the open redirect vulnerability.

WeaknessesCWE-601
AuthorsdhiyaneshDK
Template tagscvecve2020redirectepiservervuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:episerver:find:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2