Open redirect in Cisco Secure Access Control System (ACS) - CVE-2017-3840
Published: February 15, 2017 / Updated: February 17, 2017
Cisco Secure Access Control System (ACS)
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform phishing attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data when redirecting users to external websites. A remote attacker can trick the victim to follow a specially crafted link and perform phishing attacks.