CVE-2024-28239
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Summary
CVE-2024-28239 is a vulnerability affecting Directus, a real-time API and App dashboard for managing SQL database content. The authentication API contains an open redirect vulnerability, which can be exploited by manipulating the `redirect` parameter in the login process. Successful login attempts via the Auth API GET request lead users to a maliciously crafted URL, such as "directus/auth/login/google?redirect=http://malicious-fishing-site.com". Although credentials are not directly exposed, users may be tricked into clicking a seemingly legitimate Directus site, only to be redirected to a phishing site disguised as an error message requesting password updates. Users who log in via OAuth2 into Directus are at risk. Version 10.10.0 of Directus addresses this issue, and users are advised to upgrade as soon as possible. There are currently no known workarounds for this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.