MEDIUM
Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter
Published Jun 17, 2013
5.8
MEDIUMCVSS 2.0
EPSS 1.30%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.