Open Redirect Vulnerability in Cryptshare Confidential Messages

Open Redirect Vulnerability in Cryptshare Confidential Messages

CVE-2021-42564 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An open redirect through HTML injection in confidential messages in Cryptshare before 5.1.0 allows remote attackers (with permission to provide confidential messages via Cryptshare) to redirect targeted victims to any URL via the '<meta http-equiv="refresh"' substring in the editor parameter.

Learn more about our Web Application Penetration Testing UK.