CVE-2017-1000434

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
02/01/2018
Last modified:
17/01/2018

Description

Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-redirect']));

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:furikake_project:furikake:0.1.0:*:*:*:*:wordpress:*:*