An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
References
Configurations
Configuration 1 (hide)
|
History
07 Jan 2026, 21:00
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:volosoft:abp:*:*:*:*:*:*:*:* cpe:2.3:a:volosoft:abp:10.0.0:rc1:*:*:*:*:*:* |
|
| First Time |
Volosoft
Volosoft abp |
|
| References | () https://github.com/abpframework/abp/commit/44a2dc14e933f3ce1ca93f9313d836694ab77d1d - Patch | |
| References | () https://github.com/abpframework/abp/commit/a01adc58464d278ca817c4bbb6cbce30f155d0d1 - Patch |
16 Dec 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CWE | CWE-601 |
16 Dec 2025, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-16 18:16
Updated : 2026-01-07 21:00
NVD link : CVE-2025-65581
Mitre link : CVE-2025-65581
CVE.ORG link : CVE-2025-65581
JSON object : View
Products Affected
volosoft
- abp
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
