CVE-2017-7266
—CVSS 3.0
6.1 medium
EPSS
<1%p60
Published
()
Modified
Description
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.
- Vendors
- netflix
- Products
- security monkey
- Weakness
- CWE-601
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.