What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
What the vulnerability does
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP OAuth Server OAuth Server.This issue affects OAuth Server: from n/a through 4.3.3.
Explanation of Vulnerability in Simple Terms
WP OAuth Server versions up to 4.3.3 contain an open redirect vulnerability. An attacker can craft a malicious link that redirects users to an external website after they interact with the OAuth flow. The victim must click the link for the attack to succeed. This can be used for phishing or credential theft.
What an attacker can do
Redirect users to a malicious external website during the OAuth authentication process.
Potential impact on your site
Users may be phished or tricked into visiting malicious sites if they click attacker-controlled OAuth links.
Conditions required to exploit
Victim must click an attacker-crafted link containing a malicious redirect parameter.
Key dates
External resources
Related vulnerabilities