PT-2025-33890 · Totvs · Totvs Portal Meu Rh

Eduardo Schwarz

+1

·

Published

2025-08-20

·

Updated

2025-08-20

·

CVE-2025-9193

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: TOTVS Portal Meu RH versions up to 12.1.17
Description: A flaw has been identified in the Password Reset Handler component that may allow for an open redirect. Manipulation of the redirectUrl argument can lead to a redirect to an arbitrary URL. The attack can be performed remotely. This vulnerability only affects products that are no longer supported by the maintainer.
Recommendations: Upgrade to version 12.1.2410.274. Upgrade to version 12.1.2502.178. Upgrade to version 12.1.2506.121.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-9193

Affected Products

Totvs Portal Meu Rh