CVE-2019-6020: Alfasado Powercms
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
Open redirect vulnerability in PowerCMS 5.12 and earlier (PowerCMS 5.x), 4.42 and earlier (PowerCMS 4.x), and 3.293 and earlier (PowerCMS 3.x) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL.
Affected products
- Alfasado Powercms: from 3.01, up to and including 3.293; from 4.0, up to and including 4.42; from 5.0, up to and including 5.12
Published 2019-12-26. Last modified 2026-06-17.