IM
IronMonkey Threat Research

CVE-2024-7941 MEDIUM

Published: 2024-08-27 | Last Modified: 2024-10-30 | Status: Analyzed

Description

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

Additional Descriptions (1)

Un parámetro HTTP puede contener un valor de URL y podría hacer que la aplicación web redirija la solicitud a la URL especificada. Al modificar el valor de la URL de un sitio malicioso, un atacante puede iniciar con éxito una estafa de phishing y robar las credenciales del usuario.

CVSS Metrics

Base Score: 4.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-601
[email protected] Primary
en CWE-601

Affected Products

Vendor Product Version Update Type
hitachienergy microscada_x_sys600 10.5 <built-in method update of dict object at 0x72a9cc875d00> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:hitachienergy:microscada_x_sys600:10.5:*:*:*:*:*:*:*
Notification
Message here