Sploitus

CVE-2021-24288

1 known exploit for CVE-2021-24288

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

Affected products
Acymailing
Acymailing
< 7.5.0
CVSS 3.1
6.1 MEDIUM
EPSS
1.9% (78th percentile)
Weakness
CWE-601
NVD status
Modified
Published
2021-05-17
CVE-2021-24288 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2021-24288

Proof-of-concept code and exploit modules indexed by Sploitus