The Duende Identity Server based component in 1E Platform may allow URL redirections to untrusted websites.
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 4.7epss 0.2%
probabilidad de explotación
0.2%top 85% de las CVE
explotación observada
noninguna fuente lo reporta
The 1E Platform's component utilized the third-party Duende Identity Server, which suffered from an open redirect vulnerability, permitting an attacker to control the redirection path of end users.
Note: 1E Platform's component utilizing the third-party Duende Identity Server has been updated with the patch that includes the fix.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Productos afectados
1E · 1E Platform