CVE-2022-26954 Information

Description

Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter processed by the (1) ChangePassword function (2) SignInCustomerAsync function (3) SuccessfulAuthentication method or (4) NopRedirectResultExecutor class.

Reference

https://gist.github.com/adeadfed/baea45138b7eb29e09f6505d56b56413 https://github.com/nopSolutions/nopCommerce/releases

Share on: