CVE-2024-7941
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
CVSS score4.3 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:NWeakness type (CWE)CWE-601, CWE-601
Vendorshitachienergy
Affected products
| Vendors | Product | Versions |
|---|---|---|
| hitachienergy | microscada x sys600 | 10.5 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
