Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2019-14912

Description

An issue was discovered in PRiSE adAS 1.7.0. The OPENSSO module does not properly check the goto parameter, leading to an open redirect that leaks the session cookie.

POC

Reference

- https://security-garage.com/index.php/cves/from-open-redirect-to-rce-in-adas

Github

- https://github.com/0xT11/CVE-POC

- https://github.com/Wocanilo/adaPwn

- https://github.com/developer3000S/PoC-in-GitHub

- https://github.com/hectorgie/PoC-in-GitHub