VulnerabilityModified
CVE-2019-19613
The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication.
MEDIUM 5.2EPSS 0.51%
Does this matter?
Lower severity and a low EPSS score (0.51%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Halvotec RaQuest 10.23.10801.0. The login page of the admin application is vulnerable to an Open Redirect attack allowing an attacker to redirect a user to a malicious site after authentication. The attacker needs to be on the same network to modify the victim's request on the wire. Fixed in Release 24.2020.20608.0
- CVSS 3.1
- 5.2 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.51% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- halvotec/raquest
- Source
- cve@mitre.org
References
- https://excellium-services.com/cert-xlm-advisory/Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2019-19613/Third Party Advisory
- https://halvotec.de/produkte/raquest/Product, Vendor Advisory
- https://excellium-services.com/cert-xlm-advisory/Third Party Advisory
- https://excellium-services.com/cert-xlm-advisory/cve-2019-19613/Third Party Advisory
- https://halvotec.de/produkte/raquest/Product, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.