Lucene search

K
jvnJapan Vulnerability NotesJVN:75063798
HistoryJul 22, 2022 - 12:00 a.m.

JVN#75063798: Booked vulnerable to open redirect

2022-07-2200:00:00
Japan Vulnerability Notes
jvn.jp
21
open redirect vulnerability
twinkle toes software
cwe-601
phishing attack
software update

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

46.5%

Booked provided by Twinkle Toes Software contains an open redirect vulnerability (CWE-601).

Impact

When accessing a specially crafted URL, the user may be redirected to an arbitrary website. As a result, the user may become a victim of a phishing attack.

Solution

Update the software
Update the software to the latest version according to the information provided by the developer.
The developer has released Booked 3.3 that addresses the vulnerability.

Products Affected

  • Booked versions prior to 3.3

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

46.5%

Related for JVN:75063798