6.1

CVE-2020-5541

Open redirect vulnerability in CyberMail Ver.6.x and Ver.7.x allows remote attackers to redirect users to arbitrary sites and conduct phishing attacks via a specially crafted URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CybersolutionsCybermail Version6.0
CybersolutionsCybermail Version7.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.39% 0.688
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://jvn.jp/en/jp/JVN46258789/
Third Party Advisory
https://sup.cybersolutions.co.jp/otrs/customer.pl?Action=CustomerFAQZoom%3BItemID=985
https://gist.github.com/tonykuo76/ffdaa7bfabf2205dc5bac010eee38509
Third Party Advisory
https://www.chtsecurity.com/news/cf5742f8-a676-43c2-a8b9-bff17f452823
Third Party Advisory