Open Redirect Vulnerability in ePolicy Orchestrator by Trellix
CVE-2023-5445
5.4MEDIUM
What is CVE-2023-5445?
An open redirect vulnerability exists in ePolicy Orchestrator versions prior to 5.10.0 CP1 Update 2, allowing low privileged remote users to manipulate the URL parameter. This can facilitate the redirection of users to malicious sites, specifically from the dashboard area of the application. Affected users must be logged into ePolicy Orchestrator to exploit this vulnerability, which involves altering the HTTP payload after submission before it reaches the ePO server.
Affected Version(s)
ePolicy Orchestrator Prior to 5.10.0 SP1 UP2