peter bassill · operator
$ cve CVE-2015-3898 JSON

CVE-2015-3898 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 5.8% (pctl 93)

Patch early

A public exploit exists.

Description

Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the redirectUrl parameter to (1) bonita/login.jsp or (2) bonita/loginservice.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS5.84% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-601
On CISA KEVno
Public exploityes
Published2018-02-28
Last modified2026-06-17

Affected (1)

VendorProduct
bonitasoftbonita bpm portal

Public exploits

SourceTitleDate
exploit-dbBonita BPM 6.5.1 - Multiple Vulnerabilities2015-06-10

References

→ the Explorer  ·  watch your stack  ·  NVD