S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 10, 2024

CVE-2017-1000163 Scanner

Detects 'Open Redirect' vulnerability in Phoenix Framework affects v. 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2017-1000163
6.1
CVSS

The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

Phoenix Framework is a popular web development framework that is built on the Erlang Virtual Machine. It is widely used among web developers for building high-performance web applications and APIs. The framework provides a simple and elegant architecture that promotes maintainability and scalability. Phoenix Framework is also known for its rich and powerful set of features, including powerful routing, advanced real-time capabilities, and native support for WebSockets.

The CVE-2017-1000163 vulnerability is a security flaw that affects the Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0. This vulnerability allows attackers to perform unvalidated URL redirection, which could lead to phishing or social engineering attacks. In simple terms, attackers can use this vulnerability to redirect users to a malicious website without their knowledge or consent.

When exploited, this vulnerability can lead to serious consequences for users and businesses. Attackers can use unvalidated URL redirection to trick users into clicking on malicious links that can download malware onto their devices or steal sensitive information. This can result in financial losses, reputation damage, and legal implications for businesses.

In conclusion, s4e.io platform is a powerful tool that can help businesses and individuals stay up-to-date on the latest vulnerabilities affecting their digital assets. By using this platform, users can quickly and easily learn about vulnerabilities in their digital assets, including the CVE-2017-1000163 vulnerability affecting Phoenix Framework. With its pro features, s4e.io platform offers a comprehensive solution for managing and mitigating cybersecurity risks.

 

REFERENCES

Solution Advice

To protect against the CVE-2017-1000163 vulnerability, the following precautions can be taken:

  • Update to the latest version of Phoenix Framework.
  • Use a Content Security Policy (CSP) to prevent unvalidated redirects.
  • Implement URL validation checks to ensure that redirects are legitimate.
  • Use HTTP-only cookies to protect against cross-site scripting (XSS) attacks.
  • Educate users on how to identify and report suspicious links.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2017-1000163 scanner - Open Redirect vulnerability in Phoenix Framework | S4E