CVE-2018-14474

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
20/07/2018
Last modified:
29/10/2018

Description

views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:goodoldweb:orange_forum:1.4.0:*:*:*:*:*:*:*