vendor:
RiSearch and RiSearch Pro
by:
7.5
CVSS
HIGH
Open Proxy
CWE
Product Name: RiSearch and RiSearch Pro
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
RiSearch and RiSearch Pro Open Proxy Vulnerability
RiSearch and RiSearch Pro are prone to an open proxy vulnerability due to a lack of sufficient sanitization on user-supplied URI parameters. A remote attacker can exploit this vulnerability to launch attacks against local and public services in the context of the vulnerable script's host site.
Mitigation:
It is recommended to update to a fixed version of RiSearch or RiSearch Pro that properly sanitizes user-supplied URI parameters.