PT-2026-83447 · Rodauth · Rodauth
CVSS v4.0
4.9
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Rodauth versions prior to 2.47.0
Description
Insufficient validation of protocol-relative return-to paths occurs within the
confirm password, login return to requested location, and two factor auth return to requested location features. This allows attackers to use paths starting with double slashes, which browsers interpret as protocol-relative URLs, to redirect authenticated users to external malicious sites following password confirmation or login.Recommendations
Update to version 2.47.0 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rodauth