CVE-2024-8526 MEDIUM

CVE-2024-8526: Automated Logic WebCTRL and Carrier i-Vu Open Redirect

Vendor Automated Logic, A Carrier Company
Product WebCTRL
Weakness CWE-601 · Open redirect
Published November 21, 2024
Last update November 21, 2024

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability in Automated Logic WebCTRL 7.0 could allow an attacker to send a maliciously crafted URL, which when visited by an authenticated WebCTRL user, could result in the redirection of the user to a malicious webpage via "index.jsp"

Key dates

02Disclosure timeline

November 21, 2024 CVE published
November 21, 2024 Record updated