CVE-2021-24288

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
17/05/2021
Last modified:
25/05/2021

Description

When subscribing using AcyMailing, the 'redirect' parameter isn't properly sanitized. Turning the request from POST to GET, an attacker can craft a link containing a potentially malicious landing page and send it to the victim.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:acymailing:acymailing:*:*:*:*:*:wordpress:*:* 7.5.0 (excluding)