Record summary

CVE-2023-33405 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 6, 2024 · Source: CVE List

Proofs of concept

1

Repository PoCs

GitHubhacip/CVE-2023-33405Repository PoCby hacipStars: 0Not analyzed1 file

1.2 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMBlogEngine CMS - Open RedirectCVSS 6.1

Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect

Impact

Unauthenticated attackers can exploit open redirect through the years parameter to redirect users to malicious websites for phishing attacks.

Remediation

Update to the latest version of blogengine.net CMS to fix the open redirect vulnerability.

WeaknessesCWE-601
AuthorsShankar Acharya
Template tagscve2023cveBlogenginecmsredirectblogenginevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:blogengine:blogengine.net:*:*:*:*:*:*:*:*
Shodan: http.html:"blogengine.net"
FOFA: body="blogengine.net"

Source: ProjectDiscovery

References

2