Open Redirect Vulnerability in pgAdmin 4 by pgAdmin
CVE-2023-22298

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 January 2023

What is CVE-2023-22298?

An open redirect vulnerability in pgAdmin 4 allows an unauthenticated remote attacker to trick users into visiting malicious sites through specially crafted URLs. This can lead to phishing attacks where users may inadvertently enter sensitive information on untrusted websites. It is crucial for users of pgAdmin 4 versions prior to v6.14 to upgrade to ensure their security against this type of exploit.

Affected Version(s)

pgAdmin 4 versions prior to v6.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.