URL Redirection Vulnerability in YZMCMS 7.0
CVE-2024-24291

6.1MEDIUM

Key Information:

Vendor

Yzmcms

Status
Vendor
CVE Published:
6 February 2024

What is CVE-2024-24291?

YZMCMS version 7.0 is susceptible to a URL redirection vulnerability within the /member/index/login component. This flaw allows attackers to trick users into navigating to malicious sites through specially crafted URLs, posing significant risks such as phishing attacks and malware distribution. It is crucial for users and administrators to ensure proper security measures are implemented to prevent exploitation of this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.