CVE-2023-34916 describes an Open Redirect vulnerability in Fuge CMS v1.0, specifically within the /front/ProcessAct.java component. This medium-severity flaw (CVSS 6.1) allows an unauthenticated attacker to redirect users to arbitrary malicious sites with low attack complexity, potentially leading to phishing or credential theft. While no public exploits, Metasploit modules, or community discussions are currently available, organizations using Fuge CMS v1.0 should be aware of this potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:cms_project:cms:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.