Record summary

CVE-2023-6380 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List14affected
15affected

Nuclei templates

1
ProjectDiscoveryMEDIUMOpenCms 14 & 15 - Open RedirectCVSS 6.1

Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template

Impact

Unauthenticated attackers can redirect users to malicious external sites via the uri parameter, potentially facilitating phishing attacks or malware distribution.

Remediation

Update OpenCMS to version 16 or later.

WeaknessesCWE-601
AuthorsMiguelSegoviaGil
Template tagscvecve2023redirectopencmsalkaconvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:alkacon:opencms:*:*:*:*:*:*:*:*
Shodan: /opencms/
Shodan: http.title:"opencms"
Shodan: cpe:"cpe:2.3:a:alkacon:opencms"
FOFA: title="opencms"
Google: intitle:"opencms"

Source: ProjectDiscovery

References

2