id: CVE-2015-7823 info: name: Kentico CMS 8.2 Open Redirection author: 0x_Akoko description: The GetDocLink.ashx with link variable is vulnerable to open redirect vulnerability reference: - https://packetstormsecurity.com/files/133981/Kentico-CMS-8.2-Cross-Site-Scripting-Open-Redirect.html - https://nvd.nist.gov/vuln/detail/CVE-2015-7823 severity: low tags: cve,cve2015,kentico,redirect requests: - method: GET path: - "{{BaseURL}}/CMSPages/GetDocLink.ashx?link=https://example.com/" matchers: - type: regex regex: - '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)?(?:[a-zA-Z0-9\-_\.@]*)example\.com.*$' part: header