CVE-2020-28150 describes an open redirect vulnerability in I-Net Software Clear Reports version 20.10.136, where the web application improperly validates user-supplied input used in redirection links. This medium-severity vulnerability (CVSS 6.1) allows an unauthenticated attacker to redirect users to arbitrary external sites through a crafted link, potentially leading to phishing or credential theft. While user interaction is required, the attack complexity is low, and it could impact confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
20.10.136CPE matchmatch criteria | cpe:2.3:a:inetsoftware:i-net_clear_reports:20.10.136:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.