Open redirect vulnerability has been found in the Open CMS product affecting versions 14 and 15 of the 'Mercury' template. An attacker could create a specially crafted URL and send it to a specific user to redirect them to a malicious site and compromise them. Exploitation of this vulnerability is possible due to the fact that there is no proper sanitization of the 'URI' parameter.
Fixes

Solution

The vulnerabilities have been fixed in OpenCms version 16.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2024-08-28T13:44:40.334Z

Reserved: 2023-11-29T10:30:53.961Z

Link: CVE-2023-6380

cve-icon Vulnrichment

Updated: 2024-08-02T08:28:21.760Z

cve-icon NVD

Status : Modified

Published: 2023-12-13T11:15:07.630

Modified: 2024-11-21T08:43:44.820

Link: CVE-2023-6380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.