6.1
CVE-2021-25033
- EPSS 2.68%
- Veröffentlicht 14.02.2022 12:15:15
- Zuletzt bearbeitet 21.11.2024 05:54:13
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Noptin < 1.6.5 - Open Redirect
WordPress Newsletter Plugin – Noptin < 1.6.5 - Open Redirect
The WordPress Newsletter Plugin WordPress plugin before 1.6.5 does not validate the to parameter before redirecting the user to its given value, leading to an open redirect issue
Mögliche Gegenmaßnahme
Simple Newsletter Plugin – Noptin: Update to version 1.6.5, or a newer patched version
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.68% | 0.839 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
https://plugins.trac.wordpress.org/changeset/2639592
https://wpscan.com/vulnerability/c2d2384c-41b9-4aaf-b918-c1cfda58af5c
https://www.wordfence.com/threat-intel/vulnerabilities/id/c5372890-72d4-482d-a7f2-04a50520c4dc