6.1

CVE-2015-4070

Wow Moodboard Lite <= 1.1.1.1 - Open Redirect

Open redirect vulnerability in the proxyimages function in wowproxy.php in the Wow Moodboard Lite plugin 1.1.1.1 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
Mögliche Gegenmaßnahme
Wow Moodboard Lite: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wow New MediaWow Moodboard Lite Version1.1.1 SwPlatformwordpress
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Wow Moodboard Lite
Version *-1.1.1.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.41% 0.691
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

http://www.securityfocus.com/bid/75047
Third Party Advisory
VDB Entry
http://www.vapid.dhs.org/advisory.php?v=120
Third Party Advisory
https://www.wordfence.com/threat-intel/vulnerabilities/id/f815a4e5-cca2-4b86-96f4-ad956814d685
Third Party Advisory