What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in LOGON KB Support kb-support.This issue affects KB Support: from n/a through <= 1.6.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
What the vulnerability does
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in LOGON KB Support kb-support.This issue affects KB Support: from n/a through <= 1.6.7.
Explanation of Vulnerability in Simple Terms
KB Support versions 1.6.7 and earlier contain an open redirect vulnerability. When a user clicks a malicious link, the application redirects them to an attacker-controlled website without validation. This can be used to trick users into visiting phishing pages or malicious sites. The vulnerability requires user interaction and has limited confidentiality impact.
What an attacker can do
Redirect users to a malicious website by crafting a specially crafted link.
Potential impact on your site
Users may be tricked into visiting phishing or malware sites, potentially compromising their credentials or devices.
Conditions required to exploit
User must click an attacker-supplied link. No authentication required.
Key dates
External resources
Related vulnerabilities