← Back to CVE List

CVE-2020-21998

Published: 2021-04-27T18:15Z
Last Modified: 2024-11-21T05:12Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In HomeAutomation 3.3.2 input passed via the 'redirect' GET parameter in 'api.php' script is not properly verified before being used to redirect users. This can be exploited to redirect a user to an arbitrary website e.g. when a user clicks a specially crafted link to the affected script hosted on a trusted domain. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt