the web application to redirect the request to the specified URL.
By modifying the URL value to a malicious site, an attacker may
successfully launch a phishing scam and steal user credentials.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48781 | An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. |
Wed, 30 Oct 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hitachienergy:microscada_x_sys600:10.5:*:*:*:*:*:*:* |
Wed, 28 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hitachienergy
Hitachienergy microscada X Sys600 |
|
| CPEs | cpe:2.3:a:hitachienergy:microscada_x_sys600:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hitachienergy
Hitachienergy microscada X Sys600 |
Tue, 27 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Aug 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials. | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Hitachi Energy
Published:
Updated: 2024-08-27T13:12:59.267Z
Reserved: 2024-08-19T14:56:28.496Z
Link: CVE-2024-7941
Updated: 2024-08-27T13:12:55.864Z
Status : Analyzed
Published: 2024-08-27T13:15:06.467
Modified: 2024-10-30T15:29:26.673
Link: CVE-2024-7941
No data.
OpenCVE Enrichment
No data.
EUVD