CVE-2020-26219
Summary
| CVE | CVE-2020-26219 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-11-11 22:15:00 UTC |
| Updated | 2020-11-17 17:19:00 UTC |
| Description | touchbase.ai before version 2.0 is vulnerable to Open Redirect. Impacts can be many, and vary from theft of information and credentials, to the redirection to malicious websites containing attacker-controlled content, which in some cases even cause XSS attacks. So even though an open redirection might sound harmless at first, the impacts of it can be severe should it be exploitable. The issue is fixed in version 2.0. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Touchbase.ai Project | Touchbase.ai | All | All | All | All |
| Application | Touchbase.ai Project | Touchbase.ai | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Open Redirect · Advisory · puncsky/touchbase.ai · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.