CVE-2015-8474

Source
https://cve.org/CVERecord?id=CVE-2015-8474
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2015-8474.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2015-8474
Downstream
Published
2016-04-12T14:59:05Z
Modified
2025-08-09T19:01:28Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Open redirect vulnerability in the validbackurl function in app/controllers/applicationcontroller.rb in Redmine before 2.6.7, 3.0.x before 3.0.5, and 3.1.x before 3.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted backurl parameter, as demonstrated by "@attacker.com," a different vulnerability than CVE-2014-1985.

References

Affected packages