CVE-2022-28923

MEDIUM NUCLEI

Caddy < 2.5.0-beta.1 - Open Redirect via Crafted URLs

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2022-28923 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

Nuclei Templates (1)

Caddy 2.4.6 - Open Redirect
MEDIUMVERIFIEDby Sascha Brendel,DhiyaneshDk
Shodan: Server: caddy || server: caddy

References (1)

Core 1

Scores

CVSS v3 6.1
EPSS 0.0143
EPSS Percentile 69.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
caddyserver/caddy 2.4.6
caddyserver/caddy 0 - 2.5.0-beta.1Go
Published Feb 06, 2023
Tracked Since Feb 18, 2026