Record summary

CVE-2024-4940 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 24, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE ListThrough latestaffected

Default status: unknown

CVE List4.36.0affected
GitHub AdvisoryThrough 4.36.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGradio - Open RedirectCVSS 5.4

An open redirect vulnerability exists in the gradio-app/gradio, affecting the latest version. The vulnerability allows an attacker to redirect users to arbitrary websites, which can be exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling of URLs. Attackers can exploit this vulnerability by crafting a malicious URL that, when processed by the application, redirects the user to an attacker-controlled web page.

Impact

Attackers can redirect users to malicious websites via open redirect, potentially enabling phishing attacks.

Remediation

Update Gradio to a version that patches the open redirect vulnerability.

WeaknessesCWE-601
AuthorsDhiyaneshDK
Template tagscvecve2024redirectoastgradiovuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Shodan: http.html:"__gradio_mode__"
Shodan: http.title:"gradio"
FOFA: body="__gradio_mode__"
FOFA: title="gradio"
Google: intitle:"gradio"

Source: ProjectDiscovery

References

3