Количество 2
Количество 2
CVE-2025-60868
The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.
GHSA-rpjr-pcmr-9ppw
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2025-60868 The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-rpjr-pcmr-9ppw Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw | CVSS3: 6.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу