Beveiligingsadvies

CVE-2026-90453

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-11 21:51:25
Laatst bijgewerkt 2026-09-11 21:51:25
Toegewezen door icscert
CVSS-score 5.1
Status PUBLISHED

Beschrijving

A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.