Vulnerability Description
A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://medium.com/%40rajput.thakur/dom-based-malicious-redirection-cve-2024-282
- https://medium.com/%40rajput.thakur/dom-based-malicious-redirection-cve-2024-282
FAQ
What is CVE-2024-28287?
CVE-2024-28287 is a vulnerability with a CVSS score of 7.3 (HIGH). A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL.
How severe is CVE-2024-28287?
CVE-2024-28287 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-28287?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.