6.1
CVE-2023-36085
- EPSS 0.22%
- Veröffentlicht 25.10.2023 18:17:28
- Zuletzt bearbeitet 21.11.2024 08:09:15
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The sisqualWFM 7.1.319.103 thru 7.1.319.111 for Android, has a host header injection vulnerability in its "/sisqualIdentityServer/core/" endpoint. By modifying the HTTP Host header, an attacker can change webpage links and even redirect users to arbitrary or malicious locations. This can lead to phishing attacks, malware distribution, and unauthorized access to sensitive resources.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sisqualwfm ≫ Sisqualwfm SwPlatformandroid Version >= 7.1.319.103 < 7.1.319.111
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.22% | 0.445 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.1 | 2.8 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.