Open Redirect Vulnerability in LabKey Server Community Edition
CVE-2019-3912
6.1MEDIUM
What is CVE-2019-3912?
A security flaw exists in the LabKey Server Community Edition before version 18.3.0-61806.763, which allows an unauthenticated attacker to exploit the /__r1/ returnURL parameter leading to open redirection. This vulnerability can enable malicious users to redirect unsuspecting individuals to arbitrary and potentially harmful websites, posing significant risks to users' data security and privacy.
Affected Version(s)
LabKey Server Community Edition Versions before 18.3.0-61806.763
References
EPSS Score
16% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved