CVE-2019-6020

MEDIUM WAF: Medium
CVSS 6.1 Published: 2019-12-26
CWE-601

Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.

WAF Coverage Analysis

Open Redirect Medium WAF Coverage

OWASP: A01:2021 Broken Access Control

941xxx - XSS / XXE

Affected Software

VendorProductVersion
alfasadopowercms3.01 - 3.293
alfasadopowercms4.0 - 4.42
alfasadopowercms5.0 - 5.12

References

Back to CVE Database