Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Microchip TimeProvider 4100 allows XSS Through HTTP Headers.This issue affects TimeProvider 4100: from 1.0.
Problem types
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Product status
1.0 (firmware) before 2.4.7
Timeline
| 2024-06-27: | Reported |
Credits
Armando Huesca Prida
Marco Negro
Antonio Carriero
Vito Pistillo
Davide Renna
Manuel Leone
Massimiliano Brolli
TIM Security Red Team Research
References
www.microchip.com/...er-improper-verification-of-host-header
www.gruppotim.it/it/footer/red-team.html