CVE-2021-3851 describes a URL Redirection to Untrusted Site vulnerability affecting Firefly III, a personal finance manager. This medium-severity flaw (CVSS 5.4) allows an attacker to redirect authenticated users to malicious external sites through crafted links, potentially leading to credential theft or phishing. While no public exploits, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, users should remain vigilant for social engineering attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.6.2CPE matchmatch criteria | cpe:2.3:a:firefly-iii:firefly_iii:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.