6.1
CVSSv3

CVE-2023-26494

Published: 24/04/2023 Updated: 03/05/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an malicious user to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to the homepage on login. Version 3.24.1 contains a fix.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thethingsnetwork lorawan-stack