Open Redirect Vulnerability in PowerCMS by PowerCMS Inc.
CVE-2019-6020

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 December 2019

What is CVE-2019-6020?

An open redirect vulnerability exists in PowerCMS versions 5.12 and earlier, 4.42 and earlier, and 3.293 and earlier, allowing remote attackers to redirect users to arbitrary websites. This flaw can be exploited through specially crafted URLs, posing significant risks for phishing attacks, where unsuspecting users may be led to malicious sites designed to compromise their data or credentials.

Affected Version(s)

PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x)

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.