Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vfm5-cr22-jg3m | ABP Account Module has an Open Redirect through Improper validation in its register function |
Wed, 07 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Volosoft
Volosoft abp |
|
| CPEs | cpe:2.3:a:volosoft:abp:*:*:*:*:*:*:*:* cpe:2.3:a:volosoft:abp:10.0.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Volosoft
Volosoft abp |
Tue, 16 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 | |
| Metrics |
cvssV3_1
|
Tue, 16 Dec 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-16T19:14:01.242Z
Reserved: 2025-11-18T00:00:00.000Z
Link: CVE-2025-65581
Updated: 2025-12-16T19:13:46.984Z
Status : Analyzed
Published: 2025-12-16T18:16:14.820
Modified: 2026-01-07T21:00:11.100
Link: CVE-2025-65581
No data.
OpenCVE Enrichment
No data.
Github GHSA