Web / CMS

Spoofing

Unvalidated open redirection Fuge CMS v1.0

Unvalidated open redirection Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS81
PUBLISHED
2023-07-20
CVE IDs
CVE-2023-34916
VENDORS
Fuge
PUBLIC EXPLOIT
PoC public
CWE
CWE-601
PRODUCT
Fuge CMS v1.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Unvalidated open redirection Fuge CMS v1.0

The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking RETURN_URL parameter as a user input and passing it without any validation. in next lines this returnUrl parameter is being used for redirection.

Vulnerability details

Vulnerability details

CVE-2023-34916
CWE-601
Medium | 6.1

Unvalidated open redirection Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking RETURN_URL parameter as a user input and passing it without any

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-06-06 Reported On

2023-07-31 Made Public On

Fixed On: Not Fixed

Credits

Akshat Singhal