CVE-2019-12783
Last modified
CVE-2019-12783 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
An issue was discovered in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by attackers to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Verint | Impact 360 | 15.1 |
References
- http://packetstormsecurity.com/files/158412/Verint-Impact-360-15.1-Open-Redirect.htmlThird Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2020/Jul/16Mailing List, Third Party Advisory
- http://packetstormsecurity.com/files/158412/Verint-Impact-360-15.1-Open-Redirect.htmlThird Party Advisory, VDB Entry
- https://seclists.org/fulldisclosure/2020/Jul/16Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12783?
How severe is CVE-2019-12783?
How do I fix CVE-2019-12783?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-12777An issue was discovered on the ENTTEC Datagate MK2, Storm 24…
- CVE-2019-12779libqb before 1.0.5 allows local users to overwrite arbitrary…
- CVE-2019-1278An elevation of privilege vulnerability exists in the way th…7.8
- CVE-2019-12780The Belkin Wemo Enabled Crock-Pot allows command injection i…
- CVE-2019-12781An issue was discovered in Django 1.11 before 1.11.22, 2.1 b…
- CVE-2019-12782An authorization bypass vulnerability in pinboard updates in…
- CVE-2019-12784An issue was discovered in Verint Impact 360 15.1. At wfo/co…8.8
- CVE-2019-12786An issue was discovered on D-Link DIR-818LW devices from 2.0…8.8
- CVE-2019-12787An issue was discovered on D-Link DIR-818LW devices from 2.0…8.8
- CVE-2019-12788An issue was discovered in Photodex ProShow Producer v9.0.37…7.8
- CVE-2019-12789An issue was discovered on Actiontec T2200H T2200H-31.128L.0…
- CVE-2019-1279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2019-12783?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
