Open Redirect Vulnerability in Elgg by Simple Machines
CVE-2019-11016
6.1MEDIUM
What is CVE-2019-11016?
An open redirect vulnerability exists in Elgg, a popular social networking engine, due to improper validation of user-supplied input. This flaw allows an attacker to redirect users to unintended locations after authentication, which could lead to phishing attacks or other malicious activities. It affects Elgg versions prior to 1.12.18 and 2.3.x before 2.3.11, necessitating prompt updates to safeguard web applications relying on this platform.
