Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44036
HistoryOct 27, 2023 - 9:05 p.m.

Open Redirect

2023-10-2721:05:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
firefox
open redirect
vulnerability
malicious website
user awareness

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

29.5%

firefox is vulnerable to Open Redirect. An attacker could exploit this vulnerability by tricking a user into visiting a malicious website. The malicious website would contain a specially crafted link that would redirect the user to an arbitrary website. The user would not be able to see the actual URL of the destination website, so they would be unaware that they were being redirected to a malicious website.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

AI Score

7

Confidence

High

EPSS

0.001

Percentile

29.5%