Description


An issue was discovered in NetScout nGeniusONE 6.3.2 build 904. Open Redirection can occur (issue 2 of 2). After successful login, an attacker must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host. The attack vector is Network, and the Attack Complexity required is High. Privileges required are administrator, User Interaction is required, and Scope is unchanged. The user must visit the vulnerable parameter and inject a crafted payload to successfully redirect to an unknown host.

Related CPE's


Weaknesses



CWE-601

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-601

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

3.5 · Low

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2023-01-27T13:15:11.347Z

3 years ago

Last modified

2025-03-28T15:15:21.190Z

11 months ago