Automated Logic's WebCtrl Server Version 6.1 'Help' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file.
References
Link | Resource |
---|---|
https://www.corporate.carrier.com/Images/CARR-PSA-ALC-WebCTRL-001-1121_tcm558-149395.pdf | Mitigation Third Party Advisory |
Configurations
Information
Published : 2022-04-19 14:15
Updated : 2022-04-27 09:28
NVD link : CVE-2022-1019
Mitre link : CVE-2022-1019
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
automatedlogic
- webctrl_server