An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-16 18:16
Updated : 2026-01-07 21:00
NVD link : CVE-2025-65581
Mitre link : CVE-2025-65581
CVE.ORG link : CVE-2025-65581
JSON object : View
Products Affected
volosoft
- abp
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
