Web / CMS

Spoofing

Unvalidated redirection vulnerability in Fuge CMS v1.0

Unvalidated redirection vulnerability in Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is

6.1
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS80
PUBLISHED
2023-07-20
CVE IDs
CVE-2023-34917
VENDORS
Fuge
PUBLIC EXPLOIT
PoC public
CWE
CWE-601
PRODUCT
Fuge CMS v1.0
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Unvalidated redirection vulnerability in Fuge CMS v1.0

The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is taking the nextUrl parameter as a user input and passing it without any validation. in next lines this nextUrl parameter is being used for redirection.

Vulnerability details

Vulnerability details

CVE-2023-34917
CWE-601
Medium | 6.1

Unvalidated redirection vulnerability in Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is taking the nextUrl parameter as a user input and passing it

Auth:
None (remote, user interaction required)
Impact:
Limited data disclosure, limited data tampering; impact extends beyond the vulnerable component
DISCLOSURE

Disclosure timeline

2023-06-06 Reported On

2023-07-31 Made Public On

Fixed On: Not Fixed

Credits

Akshat Singhal