Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Open redirect vulnerability in startSSO.ping in the SP Endpoints in Ping Identity PingFederate 6.10.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the TargetResource parameter.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Ping Identity PingFederate 开放重定向漏洞
Vulnerability Description
Ping Identity PingFederate是美国Ping Identity公司的一套基于云端服务的企业级单点登陆(SSO)平台。该平台允许企业的雇员、消费者、顾客或合作伙伴登陆一个账号利用企业提供的多项资源。 Ping Identity PingFederate 6.10.1版本的SP Endpoints中的startSSO.ping文件中存在开放重定向漏洞。远程攻击者可借助‘TargetResource’参数中的URL利用该漏洞将用户重定向到任意网站,实施钓鱼攻击。
CVSS Information
N/A
Vulnerability Type
N/A