CVE-2018-15178
Last modified
CVE-2018-15178 is a vulnerability of currently unknown severity. Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.. EPSS estimates a 1.32% chance of exploitation in the next 30 days.
Description
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gogs | Gogs | < 0.12 |
References
- https://github.com/gogs/gogs/issues/5364Exploit, Third Party Advisory
- https://github.com/gogs/gogs/pull/5365Third Party Advisory
- https://github.com/gogs/gogs/issues/5364Exploit, Third Party Advisory
- https://github.com/gogs/gogs/pull/5365Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15178?
How severe is CVE-2018-15178?
How do I fix CVE-2018-15178?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-15172TP-Link WR840N devices have a buffer overflow via a long Aut…
- CVE-2018-15173Nmap through 7.70, when the -sV option is used, allows remot…
- CVE-2018-15174XnView 2.45 allows remote attackers to cause a denial of ser…
- CVE-2018-15175XnView 2.45 allows remote attackers to cause a denial of ser…
- CVE-2018-15176XnView 2.45 allows remote attackers to cause a denial of ser…
- CVE-2018-15177In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF at…
- CVE-2018-1518IBM InfoSphere Information Server 11.7 is affected by a weak…6.2
- CVE-2018-15180qTest Portal in QASymphony qTest Manager 9.0.0 has an Open R…
- CVE-2018-15181JioFi 4G Hotspot M2S devices allow attackers to cause a deni…
- CVE-2018-15182PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the Fir…
- CVE-2018-15183PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Sc…
- CVE-2018-15184PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4…
Are you affected by CVE-2018-15178?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
