SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-2907

Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the forwardTo parameter to redirect.do.

MEDIUM 4.9EPSS 1.47%

Does this matter?

Lower severity and a low EPSS score (1.47%). Track it; it rarely justifies an emergency change on its own.

Description

Unspecified vulnerability in SSL-Explorer before 0.2.13 allows remote authenticated users to enter redirect URLs containing (1) JavaScript or (2) HTTP headers via an unspecified vector, possibly the forwardTo parameter to redirect.do. NOTE: the impact might be cross-site scripting (XSS) or HTTP request smuggling.

CVSS 2.0
4.9 MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
EPSS
1.47% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
ssl-explorer/ssl-explorer
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.