CVE Published: 27/08/2024 |
CVE Updated: 27/08/2024 |
CVE Year: 2024 Source: Hitachi Energy |
Vendor: Hitachi Energy |
Product: MicroSCADA SYS600 Status : PUBLISHED
CVE-2024-7941 Description
An HTTP parameter may contain a URL value and could cause
the web application to redirect the request to the specified URL.
By modifying the URL value to a malicious site, an attacker may
successfully launch a phishing scam and steal user credentials.
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N