CVE-2022-25799

    Dashboard / Vulnerabilities / CVE-2022-25799

    CVE-2022-25799

    Published: 16 Aug 2022Last Modified: 12 Aug 2026

    Summary: An open redirect vulnerability exists in CERT/CC VINCE software prior to version 1.50.0

    Details: An open redirect vulnerability exists in CERT/CC VINCE software prior to 1.50.0. An attacker could send a link that has a specially crafted URL and convince the user to click the link. When an authenticated user clicks the link, the authenticated user's browser could be redirected to a malicious site that is designed to impersonate a legitimate website. The attacker could trick the user and potentially acquire sensitive information such as the user's credentials.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- b986a8637b57c5cd8b2c5722f29f9893aef3f04c

    Affected versions

    1.50.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-25799 | CVE-DB