CVE-2025-65581
EUVD-2025-20382316.12.2025, 18:16
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| volosoft | abp | 5.1.0 ≤ 𝑥 < 10.0.0 |
| volosoft | abp | 10.0.0:rc1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration