CVE-2024-7941
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
- Published Aug 27, 2024
- CVSS 4.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)