CVE-2024-27592

MEDIUM

Corezoid Process Engine <6.5.0 - Open Redirect

Title source: llm
STIX 2.1

Description

Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.

Scores

CVSS v3 4.3
EPSS 0.0052
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
corezoid/corezoid 6.5.0
Published Apr 11, 2024
Tracked Since Feb 18, 2026