CVE-2017-1000027

Koozali Foundation SME Server versions 8.x, 9.x, 10.x are vulnerable to an open URL redirect vulnerability in the user web login function resulting in unauthorized account access.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:koozali:sme_server:8.0:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:9.0:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:9.2:*:*:*:*:*:*:*
cpe:2.3:a:koozali:sme_server:10.0:*:*:*:*:*:*:*

History

07 Nov 2023, 02:37

Type Values Removed Values Added
References
  • {'url': 'https://forums.contribs.org/index.php/topic,52838.0.html', 'name': 'https://forums.contribs.org/index.php/topic,52838.0.html', 'tags': ['Third Party Advisory'], 'refsource': 'MISC'}
  • () https://forums.contribs.org/index.php/topic%2C52838.0.html -

Information

Published : 2017-07-17 13:18

Updated : 2023-12-10 12:15


NVD link : CVE-2017-1000027

Mitre link : CVE-2017-1000027

CVE.ORG link : CVE-2017-1000027


JSON object : View

Products Affected

koozali

  • sme_server
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')