KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
References
| Link | Resource |
|---|---|
| https://github.com/kalcaddle/KodExplorer/releases/tag/4.52 | Release Notes |
| https://kodcloud.com/ | Product |
| https://www.exploit-db.com/exploits/52245 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/kodexplorer-open-redirect-vulnerability-via-user-login-endpoint | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-11 22:15
Updated : 2025-12-15 18:21
NVD link : CVE-2025-34504
Mitre link : CVE-2025-34504
CVE.ORG link : CVE-2025-34504
JSON object : View
Products Affected
kodcloud
- kodexplorer
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
