CVE-2014-3739: Zenoss
Medium severity, CVSS 5.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Open redirect vulnerability in zport/acl_users/cookieAuthHelper/login_form in Zenoss 4.2.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the came_from parameter.
Affected products
- Zenoss Zenoss: version 4.2.5 only
Published 2014-05-20. Last modified 2026-06-17.