What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
What the vulnerability does
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Parcel Pro.This issue affects Parcel Pro: from n/a through 1.6.11.
Explanation of Vulnerability in Simple Terms
Parcel Pro versions up to 1.6.11 contain an open redirect vulnerability. When a user clicks a malicious link, the application redirects them to an attacker-controlled website without validation. This can be used to trick users into visiting phishing sites or malware distribution pages. The vulnerability requires user interaction and has limited confidentiality impact.
What an attacker can do
Redirect users to a malicious website when they click a crafted link.
Potential impact on your site
Users may be tricked into visiting phishing or malware sites, damaging trust and potentially compromising credentials.
Conditions required to exploit
User must click an attacker-supplied link pointing to the vulnerable application.
Key dates
External resources
Related vulnerabilities