URL Redirection Vulnerability in Dedecms by Dedecms Team
CVE-2024-57241
6.5MEDIUM
Summary
The Dedecms web application version 5.71sp1 and earlier is affected by a URL redirection vulnerability due to a logic error that fails to adequately validate input from GET requests. This flaw allows attackers to manipulate URLs, potentially leading users to malicious sites without their knowledge. It is crucial for users of Dedecms to monitor their systems and implement measures to mitigate risks associated with this vulnerability.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved