IM
IronMonkey Threat Research

CVE-2023-5986 HIGH

Published: 2023-11-15 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

Additional Descriptions (1)

Existe una vulnerabilidad CWE-601: Redireccionamiento de URL a un Sitio que No es de Confianza que podría causar una vulnerabilidad de openredirect que conduzca a un ataque de cross site scripting. Al proporcionar una entrada codificada en URL, los atacantes pueden hacer que la aplicación web del software se redirija al dominio elegido después de iniciar sesión correctamente.

CVSS Metrics

Base Score: 6.1 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 2.7

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-601
[email protected] Primary
en CWE-601

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_power_monitoring_expert 2020 <built-in method update of dict object at 0x7e60ba2a57c0> Application
schneider-electric ecostruxure_power_monitoring_expert 2020 <built-in method update of dict object at 0x7e61079ca000> Application
schneider-electric ecostruxure_power_monitoring_expert 2020 <built-in method update of dict object at 0x7e60a8974180> Application
schneider-electric ecostruxure_power_monitoring_expert 2021 <built-in method update of dict object at 0x7e60a8974600> Application
schneider-electric ecostruxure_power_monitoring_expert 2021 <built-in method update of dict object at 0x7e60bae0e100> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2020:-:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2020:cumulative_update_1:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2020:cumulative_update_2:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2021:-:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2021:cumulative_update_1:*:*:*:*:*:*
Notification
Message here