The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Strip" feature is enabled. Case variations, encoded keys, and duplicates are not removed, allowing attackers to bypass sanitization. This may lead to cache poisoning, parameter pollution, or denial of service.
                
            References
                    Configurations
                    No configuration.
History
                    10 Oct 2025, 15:16
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-290 | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 6.5 | 
10 Oct 2025, 14:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-10-10 14:15
Updated : 2025-10-14 19:36
NVD link : CVE-2025-60868
Mitre link : CVE-2025-60868
CVE.ORG link : CVE-2025-60868
JSON object : View
Products Affected
                No product.
CWE
                
                    
                        
                        CWE-290
                        
            Authentication Bypass by Spoofing
