github.com
https://github.com/u5cms/u5cms/issues/50 CVE-2022-32444
MEDIUMNuclei
u5cms v8.3.5 - Open Redirect
Record summary
CVE-2022-32444 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
An issue was discovered in u5cms verion 8.3.5 There is a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMu5cms v8.3.5 - Open RedirectCVSS 6.1
u5cms version 8.3.5 contains a URL redirection vulnerability that can cause a user's browser to be redirected to another site via /loginsave.php.
Impact
An attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks.
Remediation
Apply the latest patch or update to a version that has fixed this vulnerability.
WeaknessesCWE-601
Authors0x_Akoko
Template tagscvecve2022redirectu5cmscmsyubavuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:yuba:u5cms:8.3.5:*:*:*:*:*:*:*
https://github.com/u5cms/u5cms/issues/50 https://nvd.nist.gov/vuln/detail/CVE-2022-32444 https://github.com/ARPSyndicate/kenzer-templates https://github.com/Sharpforce/cybersecurity
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-32444