CVE-2017-15700
18.12.2017, 20:29
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.Enginsight
Vendor | Product | Version |
---|---|---|
apache | sling_authentication_service | 1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration