PoC Index

CVE-2019-14912

MEDIUM 6.1EPSS 1.2%

An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.

CVSS v3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.19% chance of exploitation in the next 30 days, 66th percentile
Published
2019-09-20
Updated
2024-08-05

Proof-of-concept exploits (2)

References

Related