S4E just found a medium snmp system information scanner
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-28923 Scanner

Detects 'Open Redirect' vulnerability in Caddy affects v. 2.4.6.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-28923
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Caddy is a web server and reverse proxy software that provides a user-friendly interface to configure and manage server functionalities. It is widely used for serving static files, running web applications, and handling HTTP/HTTPS requests. Caddy is a lightweight and efficient tool that allows developers to easily deploy web applications with minimal setup and maintenance. 

However, a critical vulnerability has been detected in Caddy version 2.4.6, identified with CVE-2022-28923. This vulnerability can allow attackers to exploit open redirection and redirect users to phishing websites while forging the URL path. Attackers can craft URLs that appear to be legitimate, but the redirect action can lead users to malicious websites that can steal their sensitive data or deploy malware on their devices.

When an attacker exploits this vulnerability, it can lead to severe consequences, such as financial loss, reputational damage, and legal consequences. The attackers can easily redirect users to phishing websites that look identical to legitimate sites, with the intention of stealing user credentials and other sensitive information. Once attackers get hold of this information, they can use it for identity theft or other illegal activities. This vulnerability can lead to significant loss of data, finance and reputation for individuals and businesses alike.

In conclusion, the vulnerability detected in Caddy version 2.4.6 can have detrimental effects on users and businesses. However, by taking the necessary precautions, the risk of exploitation can be significantly reduced. Moreover, s4e.io is a platform that offers valuable insights into vulnerabilities present in digital assets, including web servers, and provides mitigation strategies to ensure the optimal security of digital infrastructure. By utilizing the pro features of this platform, businesses and individuals can detect vulnerabilities early and mitigate them to prevent potential damages.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is advisable to take the following precautions:

  • Update Caddy to the latest version, which includes the security patch for CVE-2022-28923.
  • Implement strict URL validation and sanitization mechanisms to ensure that no malicious URLs are processed.
  • Configure appropriate security headers that prevent open redirection and other similar attacks.
  • Use web application firewalls that can detect and prevent open redirection attacks.
  • Regularly monitor server logs and web traffic to identify any suspicious activity and take necessary actions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-28923 scanner - Open Redirect vulnerability in Caddy S4E