5.8
CVSSv2

CVE-2014-7294

Published: 02/01/2015 Updated: 05/01/2015
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open redirect vulnerability in the logon page in NYU OpenSSO Integration 2.1 and previous versions for Ex Libris Patron Directory Services (PDS) allows remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nyu opensso integration

Exploits

Ex Libris Patron Directory Services version 21 suffers from an open redirection vulnerability ...