URL Validation Flaw in Oppia 3.1.4 by Oppia Foundation
CVE-2021-41733

6.1MEDIUM

Key Information:

Vendor

Oppia

Status
Vendor
CVE Published:
8 November 2021

What is CVE-2021-41733?

Oppia version 3.1.4 contains a security issue where the application does not properly verify the validity of certain URLs before navigation. This oversight could enable attackers to manipulate users into navigating to malicious sites or unintended content, increasing the risk of phishing and data exposure. It is crucial for users of this version to be aware of this vulnerability and implement security measures to mitigate potential threats.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.