Arbitrary Open Redirection Vulnerability in SolarWinds Platform
CVE-2024-28076
4.7MEDIUM
Summary
The vulnerability within the SolarWinds Platform allows an attacker to exploit improper URL parameter handling, leading to arbitrary open redirection attacks. By manipulating URL parameters, an attacker can redirect users to unintended and potentially harmful domains. This poses a significant security risk for organizations utilizing the SolarWinds Platform, as users can be unwittingly redirected to phishing sites or other malicious content. It is essential for users to apply security patches and maintain awareness of their URL handling practices to mitigate this risk.
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published