CVE-2025-34504

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kodcloud:kodexplorer:4.52:*:*:*:*:*:*:*

History

15 Dec 2025, 18:21

Type Values Removed Values Added
First Time Kodcloud kodexplorer
Kodcloud
CPE cpe:2.3:a:kodcloud:kodexplorer:4.52:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
References () https://github.com/kalcaddle/KodExplorer/releases/tag/4.52 - () https://github.com/kalcaddle/KodExplorer/releases/tag/4.52 - Release Notes
References () https://kodcloud.com/ - () https://kodcloud.com/ - Product
References () https://www.exploit-db.com/exploits/52245 - () https://www.exploit-db.com/exploits/52245 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/kodexplorer-open-redirect-vulnerability-via-user-login-endpoint - () https://www.vulncheck.com/advisories/kodexplorer-open-redirect-vulnerability-via-user-login-endpoint - Third Party Advisory

11 Dec 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 22:15

Updated : 2025-12-15 18:21


NVD link : CVE-2025-34504

Mitre link : CVE-2025-34504

CVE.ORG link : CVE-2025-34504


JSON object : View

Products Affected

kodcloud

  • kodexplorer
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')