Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-52772 | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 24 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ujcms
Ujcms ujcms |
|
| CPEs | cpe:2.3:a:ujcms:ujcms:9.6.3:*:*:*:*:*:*:* | |
| Vendors & Products |
Ujcms
Ujcms ujcms |
Tue, 17 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Mon, 16 Dec 2024 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-17T14:42:59.416Z
Reserved: 2024-12-06T00:00:00
Link: CVE-2024-55452
Updated: 2024-12-17T14:42:53.276Z
Status : Analyzed
Published: 2024-12-16T23:15:06.817
Modified: 2025-04-24T15:20:21.370
Link: CVE-2024-55452
No data.
OpenCVE Enrichment
No data.
EUVD