PT-2026-61691 · Cal.Diy · Cal.Diy
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
cal.diy versions 6.2.0 and earlier
Description
An open redirect issue exists in the conferencing OAuth callback endpoint. Attackers can redirect users to arbitrary URLs by crafting malicious state parameters, specifically exploiting the unsigned state parameter and the
onErrorReturnTo field. This allows visitors to be silently redirected from a trusted domain to attacker-controlled URLs, which can be used for phishing attacks.Recommendations
Update cal.diy to a version later than 6.2.0.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cal.Diy