Open Redirect Vulnerability in Elgg by Simple Machines
CVE-2019-11016

6.1MEDIUM

Key Information:

Vendor

Elgg

Status
Vendor
CVE Published:
8 April 2019

What is CVE-2019-11016?

An open redirect vulnerability exists in Elgg, a popular social networking engine, due to improper validation of user-supplied input. This flaw allows an attacker to redirect users to unintended locations after authentication, which could lead to phishing attacks or other malicious activities. It affects Elgg versions prior to 1.12.18 and 2.3.x before 2.3.11, necessitating prompt updates to safeguard web applications relying on this platform.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.