{"api_version":"1","generated_at":"2026-07-23T23:23:34+00:00","cve":"CVE-2019-6020","urls":{"html":"https://cve.report/CVE-2019-6020","api":"https://cve.report/api/cve/CVE-2019-6020.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-6020","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-6020"},"summary":{"title":"CVE-2019-6020","description":"Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2019-12-26 16:15:00","updated_at":"2020-01-06 18:01:00"},"problem_types":["CWE-601"],"metrics":[],"references":[{"url":"https://www.powercms.jp/news/release-powercms-201910.html","name":"https://www.powercms.jp/news/release-powercms-201910.html","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"PowerCMS 5.13 / 4.43 / 3.294 の提供を開始 | 新着情報 | PowerCMS - カスタマイズする CMS。","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/en/jp/JVN34634458/index.html","name":"http://jvn.jp/en/jp/JVN34634458/index.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"JVN#34634458: PowerCMS vulnerable to open redirect","mime":"text/xml","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-6020","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6020","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"6020","vulnerable":"1","versionEndIncluding":"3.293","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alfasado","cpe5":"powercms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6020","vulnerable":"1","versionEndIncluding":"4.42","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alfasado","cpe5":"powercms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"6020","vulnerable":"1","versionEndIncluding":"5.12","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alfasado","cpe5":"powercms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-6020","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Alfasado Inc.","product":{"product_data":[{"product_name":"PowerCMS","version":{"version_data":[{"version_value":"5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x)"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Open Redirect"}]}]},"references":{"reference_data":[{"url":"https://www.powercms.jp/news/release-powercms-201910.html","refsource":"MISC","name":"https://www.powercms.jp/news/release-powercms-201910.html"},{"url":"http://jvn.jp/en/jp/JVN34634458/index.html","refsource":"MISC","name":"http://jvn.jp/en/jp/JVN34634458/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL."}]}},"nvd":{"publishedDate":"2019-12-26 16:15:00","lastModifiedDate":"2020-01-06 18:01:00","problem_types":["CWE-601"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*","versionStartIncluding":"3.01","versionEndIncluding":"3.293","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0","versionEndIncluding":"4.42","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alfasado:powercms:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndIncluding":"5.12","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"6020","Ordinal":"143674","Title":"CVE-2019-6020","CVE":"CVE-2019-6020","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"6020","Ordinal":"1","NoteData":"Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"6020","Ordinal":"2","NoteData":"2019-12-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"6020","Ordinal":"3","NoteData":"2019-12-26","Type":"Other","Title":"Modified"}]}}}