In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2021-04-27T17:46:42
Updated: 2024-08-04T14:30:33.558Z
Reserved: 2020-08-13T00:00:00
Link: CVE-2020-21998
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-04-27T18:15:07.837
Modified: 2024-11-21T05:12:59.800
Link: CVE-2020-21998
Redhat
No data.