CVE-2024-7941

Medium4.3Published on August 27, 2024

An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.

CVSS score4.3 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness type (CWE)CWE-601, CWE-601
Vendorshitachienergy

Affected products

VendorsProductVersions
hitachienergymicroscada x sys60010.5

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database