IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.twcert.org.tw/tw/cp-132-4053-6e9a2-1.html | Third Party Advisory | 
Configurations
                    Information
                Published : 2020-10-14 06:15
Updated : 2020-10-26 10:46
NVD link : CVE-2020-24551
Mitre link : CVE-2020-24551
JSON object : View
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
                iproom
- mmc\+
 


