Логотип exploitDog
bind:CVE-2025-71244
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-71244

Количество 4

Количество 4

ubuntu логотип

CVE-2025-71244

около 2 месяцев назад

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-71244

около 2 месяцев назад

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-71244

около 2 месяцев назад

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-86cf-7cvr-x43r

около 2 месяцев назад

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-71244

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2025-71244

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2025-71244

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form ...

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-86cf-7cvr-x43r

SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.

CVSS3: 6.1
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу