Vulnerability Description
An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zurmo | Zurmo Crm | 3.2.1.57987acc3018 |
Related Weaknesses (CWE)
References
- https://bitbucket.org/zurmo/zurmo/issues/431/open-url-redirects-unvalidated-rediIssue Tracking
- https://bitbucket.org/zurmo/zurmo/issues/431/open-url-redirects-unvalidated-rediIssue Tracking
FAQ
What is CVE-2017-16569?
CVE-2017-16569 is a vulnerability with a CVSS score of 4.8 (MEDIUM). An Open URL Redirect issue exists in Zurmo 3.2.1.57987acc3018 via an http: URL in the redirectUrl parameter to app/index.php/meetings/default/createMeeting.
How severe is CVE-2017-16569?
CVE-2017-16569 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-16569?
Check the references section above for vendor advisories and patch information. Affected products include: Zurmo Zurmo Crm.