Open Redirect Vulnerability in Verint Impact 360 by Verint Systems
CVE-2019-12783

6.1MEDIUM

Key Information:

Vendor

Verint

Vendor
CVE Published:
14 July 2020

What is CVE-2019-12783?

An open redirect flaw exists in Verint Impact 360 15.1, found at wfo/control/signin, where the 'rd' parameter can redirect users to a malicious URL after login. This vulnerability, when exploited alongside another issue, enables attackers to execute automated brute force login attempts indirectly, potentially leading to the compromise of valid user credentials without direct interaction with the target system.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.