CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
When using local accounts for administration, the redirect url parameter was not encoded correctly, allowing for an XSS attack providing admin login. | 8.1 |
High |
||
A URL parameter during login flow was vulnerable to injection. An attacker could insert a malicious domain in this parameter, which would redirect the user after auth and send the authorization token to the redirected domain. | 8.2 |
High |