5.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 8.6 / Impact: 4.9
Source: NVD
Description
Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.
Affected (9)
Products: Orchardproject: Orchard
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0.20 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1.30 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.2.41 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.3.10 |
References (12)
Source: cve@mitre.org
Source: cve@mitre.org
Exploit
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.