An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.
- https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adas
- https://github.com/0xT11/CVE-POC
- https://github.com/Wocanilo/adaPwn
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/hectorgie/PoC-in-GitHub