What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
What the vulnerability does
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CodePeople Calculated Fields Form.This issue affects Calculated Fields Form: from n/a through 1.2.28.
Explanation of Vulnerability in Simple Terms
Calculated Fields Form versions up to 1.2.28 contain an open redirect vulnerability. An attacker with low-level user access can craft a malicious link that redirects users to an external website after they interact with the form. The redirect happens because user-supplied input is not validated before being used in a redirect operation. This can be used to phish credentials or distribute malware.
What an attacker can do
Redirect users to a malicious external website via a crafted form link.
Potential impact on your site
Users can be tricked into visiting phishing or malware sites, damaging site reputation and user trust.
Conditions required to exploit
Attacker needs low-level user account access; victim must click the malicious link.
Key dates
External resources
Related vulnerabilities