packetstormsecurity.com
http://packetstormsecurity.com/files/164345/PlaceOS-1.2109.1-Open-Redirection.html CVE-2021-41826
MEDIUMNuclei
PlaceOS 1.2109.1 - Open Redirection
Record summary
CVE-2021-41826 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMPlaceOS 1.2109.1 - Open RedirectionCVSS 6.1
PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
Remediation
Apply the latest security patch or update to PlaceOS 1.2109.2 or higher to fix the open redirection vulnerability.
WeaknessesCWE-601
Authorsgeeknik
Template tagscve2021cveredirectedbpacketstormplaceosplacevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:place:placeos_authentication:*:*:*:*:*:*:*:*
https://github.com/PlaceOS/auth/issues/36 https://www.exploit-db.com/exploits/50359 https://nvd.nist.gov/vuln/detail/CVE-2021-41826 http://packetstormsecurity.com/files/164345/PlaceOS-1.2109.1-Open-Redirection.html https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
3github.com
https://github.com/PlaceOS/auth/issues/36 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-41826