Логотип exploitDog
bind:CVE-2025-60868
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-60868

Количество 2

Количество 2

nvd логотип

CVE-2025-60868

4 месяца назад

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rpjr-pcmr-9ppw

4 месяца назад

Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-60868

The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-rpjr-pcmr-9ppw

Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу