VulnerabilityModified
CVE-2020-21998
This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
MEDIUM 6.1EPSS 1.32%
Does this matter?
Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.
Description
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.32% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- homeautomation project/homeautomation
- Source
- cve@mitre.org
References
- https://cxsecurity.com/issue/WLB-2019120132Exploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5559.phpExploit, Third Party Advisory
- https://cxsecurity.com/issue/WLB-2019120132Exploit, Third Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5559.phpExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.