Record summary

CVE-2021-41826 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMPlaceOS 1.2109.1 - Open RedirectionCVSS 6.1

PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

Impact

An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.

Remediation

Apply the latest security patch or update to PlaceOS 1.2109.2 or higher to fix the open redirection vulnerability.

WeaknessesCWE-601
Authorsgeeknik
Template tagscve2021cveredirectedbpacketstormplaceosplacevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:place:placeos_authentication:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3