ZeroHour

CVE-2021-42564

PoC
CVSS 3.1
5.4 medium
EPSS
<1%p50
Published
()
Modified
Description

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

Vendors
cryptshare
Products
cryptshare server
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.