CVE-2019-1010290
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Babel: Multilingual site Babel All is affected by: Open Redirection. The impact is: Redirection to any URL, which is supplied to redirect.php in a "newurl" parameter. The component is: redirect.php. The attack vector is: The victim must open a link created by an attacker. Attacker may use any legitimate site using Babel to redirect user to a URL of his/her choosing.
Babel: todos los sitios Babel multilingüe están afectados por: Redireccionamiento Abierto. El impacto es: Redireccionamiento en cualquier URL, que es suministrado en un archivo redirect.php en un parámetro "newurl". El componente es: el archivo redirect.php. El vector de ataque es: La víctima debe abrir un enlace diseñado por un atacante. El atacante puede usar cualquier sitio legítimo usando Babel para redireccionar al usuario a una URL de su elección.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-03-20 CVE Reserved
- 2019-07-16 CVE Published
- 2024-01-12 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://untrustednetwork.net/en/2019/02/20/open-redirection-vulnerability-in-babel | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://dev.cmsmadesimple.org/project/files/729 | 2019-07-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cmsmadesimple Search vendor "Cmsmadesimple" | Bable:multilingual Site Search vendor "Cmsmadesimple" for product "Bable:multilingual Site" | <= 0.4.1 Search vendor "Cmsmadesimple" for product "Bable:multilingual Site" and version " <= 0.4.1" | cms_made_simple |
Affected
|