First published: Wed Aug 02 2017(Updated: )
XOOPS Core 2.5.8 has a stored URL redirect bypass vulnerability in /modules/profile/index.php because of the URL filter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
E-xoops | =2.5.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-12138 is rated as a medium severity vulnerability due to the potential for exploitation through URL redirection.
To fix CVE-2017-12138, upgrade to the latest version of XOOPS that addresses this vulnerability.
CVE-2017-12138 allows attackers to bypass URL filters, which can lead to untrusted redirects affecting user security.
CVE-2017-12138 can be exploited by unauthenticated attackers, making it critical to address quickly.
CVE-2017-12138 specifically affects XOOPS Core version 2.5.8.