CVE-2025-54066

DiracX-Web is a web application that provides an interface to interact with the DiracX services. Prior to version 0.1.0-a8, an attacker can forge a request that they can pass to redirect an authenticated user to another arbitrary website. In the login page, DiracX-Web has a `redirect` field which is the location where the server will redirect the user. This URI is not verified, and can be an arbitrary URI. Paired with a parameter pollution, an attacker can hide their malicious URI. This could be used for phishing, and extract new data (such as redirecting to a new "log in" page, and asking another time credentials). Version 0.1.0-a8 fixes this vulnerability.
Configurations

No configuration.

History

17 Jul 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-17 15:15

Updated : 2025-07-17 21:15


NVD link : CVE-2025-54066

Mitre link : CVE-2025-54066

CVE.ORG link : CVE-2025-54066


JSON object : View

Products Affected

No product.

CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')