Vulnerabilities (CVE)

Filtered by vendor Volosoft Subscribe
Filtered by product Abp
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-65581 1 Volosoft 1 Abp 2026-01-07 N/A 5.3 MEDIUM
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.