go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

IProom MMC+ Server - URL Redirection to Untrusted Site (Open Redirect')

TVN ID TVN-202009001
CVE ID CVE-2020-24551
CVSS 6.1 (Medium)
(CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Affected Products IProom MMC+ Server v3.2.2
Description IProom MMC+ Server login page does not validate specific parameters properly. Attackers can use the vulnerability to redirect to any malicious site and steal the victim's login credentials.
Solution Contact IProom for tech support.
Credit Sam
Public Date 2020-10-14
Top