SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-21998

This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

MEDIUM 6.1EPSS 1.32%

Does this matter?

Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.

Description

In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
homeautomation project/homeautomation
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.