CVE-2019-3912
18Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 4.8%
exploitation probability
4.8%top 9% of all CVEs
observed exploitation
nono source reports it
An open redirect vulnerability in LabKey Server Community Edition before 18.3.0-61806.763 via the /__r1/ returnURL parameter allows an unauthenticated remote attacker to redirect users to arbitrary web sites.
Affected products
Tenable · LabKey Server Community Edition