CVE-2023-49394

Zentao versions 4.1.3 and before has a URL redirect vulnerability, which prevents the system from functioning properly.
Configurations

Configuration 1 (hide)

cpe:2.3:a:easycorp:zentao:*:*:*:*:*:*:*:*

History

17 Jan 2024, 13:33

Type Values Removed Values Added
CWE CWE-601
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://gist.github.com/xue-yao-go/87d088fa3f423bba8098ef22988e4626 - () https://gist.github.com/xue-yao-go/87d088fa3f423bba8098ef22988e4626 - Exploit, Third Party Advisory
References () https://narrow-payment-2cd.notion.site/zentao-4-1-3-is-vulnerable-URL-redirect-b03f8f9f5b4e4cbea819c2961c097d92?pvs=4 - () https://narrow-payment-2cd.notion.site/zentao-4-1-3-is-vulnerable-URL-redirect-b03f8f9f5b4e4cbea819c2961c097d92?pvs=4 - Exploit, Third Party Advisory
CPE cpe:2.3:a:easycorp:zentao:*:*:*:*:*:*:*:*
First Time Easycorp
Easycorp zentao

10 Jan 2024, 13:56

Type Values Removed Values Added
Summary
  • (es) Las versiones 4.1.3 y anteriores de Zentao tienen una vulnerabilidad de redireccionamiento de URL, que impide que el sistema funcione correctamente.

10 Jan 2024, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-10 09:15

Updated : 2024-01-17 13:33


NVD link : CVE-2023-49394

Mitre link : CVE-2023-49394

CVE.ORG link : CVE-2023-49394


JSON object : View

Products Affected

easycorp

  • zentao
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')