CVE Published: 19/04/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: icscert |
Vendor: Automated Logic |
Product: WebCtrl Server Status : PUBLISHED
CVE-2022-1019 Description
Automated Logic\'s WebCtrl Server Version 6.1 \'Help\' index pages are vulnerable to open redirection. The vulnerability allows an attacker to send a maliciously crafted URL which could result in redirecting the user to a malicious webpage or downloading a malicious file.
Metrics
CVSS Version: 3.1 |
Base Score: 5.2 MEDIUM Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N