516
VMScore

CVE-2019-12783

Published: 14/07/2020 Updated: 16/07/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

An issue exists in Verint Impact 360 15.1. At wfo/control/signin, the rd parameter can accept a URL, to which users will be redirected after a successful login. In conjunction with CVE-2019-12784, this can be used by malicious users to "crowdsource" bruteforce login attempts on the target site, allowing them to guess and potentially compromise valid credentials without ever sending any traffic from their own machine to the target site.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

verint impact 360 15.1

Exploits

Verint Impact 360 version 151 suffers from a cross site request forgery vulnerability ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Verint Impact 360 onLogin open redirect <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Ryan Delaney &lt; ...