CVE-2024-24764

CVSS v3 Score
4.8
Medium

Vulnerability Description

October is a self-hosted CMS platform based on the Laravel PHP Framework. This issue affects authenticated administrators who may be redirected to an untrusted URL using the PageFinder schema. The resolver for the page finder link schema (`october://`) allowed external links, therefore allowing an open redirect outside the scope of the active host. This vulnerability has been patched in version 3.5.15.

CVSS:4.8(Medium)

An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.

CVSS:4.8(Medium)

Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a ...

CVSS:4.8(Medium)

Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open red...

CVSS:4.8(Medium)

Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted r...

CVSS:4.8(Medium)

In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible

CVSS:4.8(Medium)

Open Redirect in GitHub repository alextselegidis/easyappointments prior to 1.5.0.