ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

1 result for “CVE-2020-21998”

CVEPublishedCVSSShadowTrackr CVSSSummary
CVE:
CVE-2020-21998
Published
2021-04-27
CVSS:
6.1
ShadowTrackr CVSS:
1.2
Summary:
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain.