Legrand SMS PowerView Open Redirect Vulnerability

Vulnerability

An open redirect vulnerability has been identified in Legrand SMS PowerView version 1.x. This issue arises from the manipulation of the 'redirect' argument, allowing remote attackers to redirect users to external sites, potentially facilitating phishing attacks. The vulnerability is related to integrity issues, as it can be exploited by injecting user-controlled input that specifies a link to an external site, which the application then uses to redirect users.

Impact

Exploitation of this vulnerability allows for open redirection, where users can be sent to malicious websites, increasing the risk of phishing attacks.

Reproduction

The vulnerability can be reproduced by sending a request to the application with the 'redirect' parameter set to an external URL. The application will then redirect the user to the specified URL, bypassing any security measures that may be in place.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.