An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
http://www.adas-sso.com/es/extra/download.php | vendor advisory |
https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adas | third party advisory exploit |