CVE-2024-12990: ruifang-tech Rebuild Admin Verification Page admin-verify redirect
A vulnerability was found in ruifang-tech Rebuild 3.8.6. It has been classified as problematic. This affects an unknown part of the file /user/admin-verify of the component Admin Verification Page. The manipulation of the argument nexturl with the input http://localhost/evil.html leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12990?
CVE-2024-12990 has been classified as problematic, indicating a significant impact on the affected component.
How do I fix CVE-2024-12990?
To fix CVE-2024-12990, ensure proper validation and sanitization of the 'nexturl' parameter in the Admin Verification Page.
What component is affected by CVE-2024-12990?
CVE-2024-12990 affects the Admin Verification Page of the ruifang-tech Rebuild 3.8.6 software.
Could CVE-2024-12990 lead to a security breach?
Yes, CVE-2024-12990 could potentially allow an attacker to manipulate input and execute unauthorized actions.
Is there a patch available for CVE-2024-12990?
As of now, specific details about a patch for CVE-2024-12990 have not been disclosed.