Advisories

Plexus anblick Digital Signage Management 3.1.13 Open Redirect via Pagina Parameter

Go Back
severity
medium
date
Affecting
  • Plexus anblick Digital Signage Management 3.1.13

CWE
  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
CVSS
5.1
CVSS V4 Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Credit
LiquidWorm as Gjoko Krstic of Zero Science Lab
Description
Plexus anblick Digital Signage Management 3.1.13 contains an open redirect vulnerability in the 'PantallaLogin' script that allows attackers to manipulate the 'pagina' GET parameter. Attackers can craft malicious links that redirect users to arbitrary websites by exploiting improper input validation in the parameter.