CVE-2021-24406

wpForo Forum <= 1.9.6 - Open Redirect

mediumURL Redirection to Untrusted Site ('Open Redirect')
6.1
CVSS Score
6.1
CVSS Score
medium
Severity
1.9.7
Patched in
953d
Time to patch

Description

The wpForo Forum WordPress plugin before 1.9.7 did not validate the redirect_to parameter in the login form of the forum, leading to an open redirect issue after a successful login. Such issue could allow an attacker to induce a user to use a login URL redirecting to a website under their control and being a replica of the legitimate one, asking them to re-enter their credentials (which will then in the attacker hands)

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Low
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=1.9.6
PublishedJune 14, 2021
Last updatedJanuary 22, 2024
Affected pluginwpforo

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.