Xsuite 2.4.4.5 and prior contains an open redirect vulnerability, which can allow a remote attacker to redirect users to arbitrary web sites and conduct phishing attacks via a malicious URL in the redirurl parameter.
id: CVE-2015-4668
info:
name: Xsuite <=2.4.4.5 - Open Redirect
author: 0x_Akoko
severity: med
...