CVE-2023-5986

CWE-601Open Redirect3 documents3 sources

Description

A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.7

Affected Packages4 packages

CVEListV5schneider_electric/ecostruxure_power_monitoring_expert_(pme)Version 2020 CU2 and prior, Version 2021 CU1 and prior+1
CVEListV5schneider_electric/ecostruxure_power_operation_(epo)_–_advanced_reporting_and_dashboards_moduleAdvanced Reporting and Dashboards Module 2020 prior to CU3, Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021+1

🔴Vulnerability Details

2
CVEList
CVE-2023-5986: A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting atta2023-11-15
GHSA
GHSA-grp5-2x24-q4vj: A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting atta2023-11-15
CVE-2023-5986 (MEDIUM CVSS 6.1) | A CWE-601 URL Redirection to Untrus | cvebase.io