RULE(RULE ID:337186)

Rule General Information
Release Date: 2022-11-28
Rule Name: EyouCMS Open Redirect Vulnerability (CVE-2021-39501)
Severity:
CVE ID:
Rule Protection Details
Description: EyouCMS is an open source content management system based on ThinkPHP from China's Zanzan Network Technology company. EyouCMS 1.5.4 is vulnerable to open redirection attacks. An attacker can redirect a user to a malicious url through the logoff function.
Impact: The server does not check and control the incoming redirect URL variables, and attackers can maliciously construct any malicious address to induce users to jump to malicious websites.
Affected OS: Windows, Linux, Others
Reference: https://github.com/KietNA-HPT/CVE
https://github.com/eyoucms/eyoucms/issues/17
Solutions
Refer to the announcement or patch by the vendor: https://www.eyoucms.com/