Avi Vantage before 17.2.13 uses an invalid URL encoding during a redirect operation, aka AV-33959.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://avinetworks.com/docs/17.2/release-notes/ | release notes vendor advisory |