← All CVEs

CVE-2011-5252

medium · 5.8

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Open redirect vulnerability in Users/Account/LogOff in Orchard 1.0.x before 1.0.21, 1.1.x before 1.1.31, 1.2.x before 1.2.42, and 1.3.x before 1.3.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the ReturnUrl parameter.

5.8
CVSS
11.9%
EPSS (exploit prob.)
96th
EPSS percentile
2013-01-12
Published

AV:N/AC:M/Au:N/C:P/I:P/A:N

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
orchardprojectorchard1.0
orchardprojectorchard1.0.20
orchardprojectorchard1.1
orchardprojectorchard1.1.30
orchardprojectorchard1.2
orchardprojectorchard1.2.41
orchardprojectorchard1.3
orchardprojectorchard1.3.9
orchardprojectorchard1.3.10

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2011-5252