What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
What the vulnerability does
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.9.
Explanation of Vulnerability in Simple Terms
Zephyr Project Manager versions up to 3.3.9 contain an open redirect vulnerability. An attacker can craft a malicious link that redirects users to an external website after they interact with the application. The vulnerability requires user interaction and has limited confidentiality impact. No authentication is required to exploit this issue.
What an attacker can do
Redirect users to a malicious external website via a crafted link.
Potential impact on your site
Users may be tricked into visiting phishing or malware sites, damaging trust in your application.
Conditions required to exploit
User must click a malicious link or visit a page containing the redirect.
Key dates
External resources
Related vulnerabilities