CVE-2018-14474 describes an Open Redirection vulnerability in Orange Forum version 1.4.0, specifically within the views/auth.go component. This flaw allows an attacker to redirect users to arbitrary external websites by manipulating the 'next' parameter during login or signup. Rated as Medium severity (CVSS 6.1), exploitation requires user interaction (UI:R) but can be executed remotely with low attack complexity (AV:N/AC:L). While not actively exploited (KEV: No) and lacking public Metasploit or ExploitDB modules, Nuclei templates exist for detection, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:goodoldweb:orange_forum:1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.