logo

Database

Description

The system does not validate that profile image URLs lead to a valid image, allowing partial paths or URLs to be placed that can be used to craft more complex attack vectors such as controlled redirects or CSRF.

Impact

Manipulate the application to send redirects to third-party pages and load content from unverified sources.

Recommendation

Validate that the URLs provided in the profile images lead to valid images.

Threat

Attacker with access to the application from the Internet.

Expected Remediation Time

⏱️ 60 minutes.

Fixes

Score

Default score using CVSS 4.0. It may change depending on the context of the src.

Base 4.0

Attack vector

N

Attack complexity

L

Attack requirements

N

Privileges required

L

User interaction

P

Confidentiality (VC)

N

Integrity (VI)

L

Availability (VA)

N

Confidentiality (SC)

N

Integrity (SI)

N

Availability (SA)

N

Threat 4.0

Exploit maturity

X

Vector string

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N