216.73.216.197

CVE-2024-1440

· Published 02/06/2025 17:15 · Modified 02/06/2025 17:32

Labels: CVE-2024-1440 2025-06-02CVE-2024-1440CWE-601ed10eef1-636d-4fbe-9993-6890dfa878f8

Essential information

Published
02/06/2025 17:15
Modified
02/06/2025 17:32
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

CVSS metrics

Description

An open redirection vulnerability exists in multiple WSO2 products due to improper validation of the multi-option URL in the authentication endpoint when multi-option authentication is enabled. A malicious actor can craft a valid link that redirects users to an attacker-controlled site. By exploiting this vulnerability, an attacker may trick users into visiting a malicious page, enabling phishing attacks to harvest sensitive information or perform other harmful actions.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8
NVD
View on NVD

Affected products (CPE)

ProductCPE
wso2 / wso2 products cpe:2.3:a:wso2:wso2_products:*:*:*:*:*:*:*:*

References