Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-16652
HistoryJun 13, 2018 - 4:29 p.m.

Open redirect

2018-06-1316:29:00
PRIOn knowledge base
www.prio-n.com
4

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.7%

An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler takes the content of the _target_path parameter and generates a redirect response, but no check is performed on the path, which could be an absolute URL to an external domain. This Open redirect vulnerability can be exploited for example to mount effective phishing attacks.

6.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

41.7%