Description
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.
Problem types
CWE-601 URL redirection to untrusted site ('open redirect')
Product status
Any version before 08/07/2025
08/07/2025 (date)
References
www.incibe.es/...o/multiple-vulnerabilities-password-manager