← Back to CVE List

CVE-2022-26954

Published: 2022-10-20T11:15Z
Last Modified: 2024-11-21T06:54Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt