An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://www.uffizio.com/ | product |
https://www.cisa.gov/news-events/ics-advisories/icsa-21-287-02 | third party advisory us government resource |