Vulnerabilities > CVE-2014-8870 - Arbitrary URI Redirection vulnerability in Tapatalk for WoltLab Burning Board

047910
CVSS 5.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
tapatalk

Summary

Open redirect vulnerability in mobiquo/smartbanner/welcome.php in the Tapatalk (com.tapatalk.wbb4) plugin before 1.1.2 for Woltlab Burning Board 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the board_url parameter. <a href="http://cwe.mitre.org/data/definitions/601.html">CWE-601: URL Redirection to Untrusted Site ('Open Redirect')</a>

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/129926/woltlab-redirect.txt
idPACKETSTORM:129926
last seen2016-12-05
published2015-01-13
reporterredteam-pentesting.de
sourcehttps://packetstormsecurity.com/files/129926/WoltLab-Burning-Board-4.0-Tapatalk-Open-Redirect.html
titleWoltLab Burning Board 4.0 Tapatalk Open Redirect