Vulnerabilities
Vulnerable Software
A flaw in the org.apache.sling.auth.core.AuthUtil#isRedirectValid method in Apache Sling Authentication Service 1.4.0 allows an attacker, through the Sling login form, to trick a victim to send over their credentials.
CVSS Score
8.8
EPSS Score
0.002
Published
2017-12-18


Contact Us

Shodan ® - All rights reserved