A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
2023-11-15T04:15:19.487
2024-11-21T08:42:55.557
Modified
CVSSv3.1: 8.2 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | schneider-electric | ecostruxure_power_monitoring_expert | 2020 | Yes |
| Application | schneider-electric | ecostruxure_power_monitoring_expert | 2020 | Yes |
| Application | schneider-electric | ecostruxure_power_monitoring_expert | 2020 | Yes |
| Application | schneider-electric | ecostruxure_power_monitoring_expert | 2021 | Yes |
| Application | schneider-electric | ecostruxure_power_monitoring_expert | 2021 | Yes |