First published: Fri Feb 16 2018(Updated: )
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F-Secure Radar | <=3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6324 is classified as a medium severity vulnerability due to potential security risks associated with unvalidated redirects.
To fix CVE-2018-6324, update F-Secure Radar to version 3.9.2 or later, which addresses the unvalidated redirect issue.
CVE-2018-6324 can lead to phishing attacks by allowing attackers to redirect users to malicious sites after login.
F-Secure Radar versions prior to 3.9.2 are affected by CVE-2018-6324.
Organizations using versions of F-Secure Radar before 3.9.2 are at risk of exploitation through unvalidated redirects.