CVE-2021-24288
When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.
- Affected products
- Acymailing
- Acymailing
- < 7.5.0
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 1.9% (78th percentile)
- Weakness
- CWE-601
- NVD status
- Modified
- Published
- 2021-05-17
CVE-2021-24288 at NVD
1 known exploit for CVE-2021-24288
Proof-of-concept code and exploit modules indexed by Sploitus