Multiple open redirect vulnerabilities in Pligg 1.0.2 and...
Moderate severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Apr 11, 2025
Description
Published by the National Vulnerability Database
Apr 21, 2010
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Apr 11, 2025
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.
References