6.1
CVSSv3

CVE-2023-33405

Published: 21/06/2023 Updated: 28/06/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Blogengine.net 3.3.8.0 and previous versions is vulnerable to Open Redirect.

Vulnerable Product Search on Vulmon Subscribe to Product

blogengine blogengine.net

Vendor Advisories

Check Point Reference: CPAI-2023-1439 Date Published: 15 Jan 2024 Severity: Medium ...

Github Repositories

CVE-2023-33405 Open Redirection vulnerability identified on BlogEngineNET CMS (version 3380 and earlier) If a GET request to defaultaspx page contains "years=" within the URL, the application calls a function named "Redirect" This function sets several parameters including year, month, date, page and rewrite Though the date parameter was parsed using