Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
References
Link | Resource |
---|---|
https://forums.contribs.org/index.php/topic,52838.0.html | Third Party Advisory |
https://cp270.wordpress.com/2017/02/02/security-advisory-open-url-redirect-in-sme-server/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-07-17 06:18
Updated : 2017-07-21 09:25
NVD link : CVE-2017-1000027
Mitre link : CVE-2017-1000027
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
koozali
- sme_server