VulnerabilityModified
CVE-2008-2052
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
MEDIUM 6.1EPSS 1.57%
Does this matter?
Lower severity and a low EPSS score (1.57%). Track it; it rarely justifies an emergency change on its own.
Description
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.57% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- bitrix24/bitrix site manager
- Source
- cve@mitre.org
References
- http://holisticinfosec.org/content/view/62/45/Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42157Third Party Advisory, VDB Entry
- http://holisticinfosec.org/content/view/62/45/Broken Link
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42157Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.