Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc8g-5x2c-p65r

Опубликовано: 24 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.

An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.

EPSS

Процентиль: 25%
0.00088
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
около 2 месяцев назад

An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.

EPSS

Процентиль: 25%
0.00088
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-601