icon

We found results for “

WS-2022-0315

Good to know:

icon

Date: August 28, 2022

planka before 1.7.4 is vulnerable to forced browsing, which can lead to phishing attacks (for example, redirecting the site to a fake login page). This can also lose data because Planka allows redirects without requesting that the user confirm leaving the page.

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Direct Request ('Forced Browsing')

CWE-425

Top Fix

icon

Upgrade Version

Upgrade to version v1.7.4

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us