github.com
https://github.com/hacip/CVE-2023-33405 CVE-2023-33405
MEDIUMNuclei
BlogEngine CMS - Open Redirect
Record summary
CVE-2023-33405 has a selected CVSS score of 6.1 (medium); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
Description source: CVE List
Exploitation context
Proofs of concept
1Repository PoCs
GitHubhacip/CVE-2023-33405Repository PoCby hacipStars: 0Not analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMBlogEngine CMS - Open RedirectCVSS 6.1
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect
Impact
Unauthenticated attackers can exploit open redirect through the years parameter to redirect users to malicious websites for phishing attacks.
Remediation
Update to the latest version of blogengine.net CMS to fix the open redirect vulnerability.
WeaknessesCWE-601
AuthorsShankar Acharya
Template tagscve2023cveBlogenginecmsredirectblogenginevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:blogengine:blogengine.net:*:*:*:*:*:*:*:*
Shodan: http.html:"blogengine.net"
FOFA: body="blogengine.net"
https://github.com/hacip/CVE-2023-33405 https://nvd.nist.gov/vuln/detail/CVE-2023-33405 https://github.com/nomi-sec/PoC-in-GitHub
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-33405