PT-2025-40019 · Corezoid · Corezoid

Published

2025-09-30

·

Updated

2025-12-23

·

CVE-2024-55017

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Corezoid version 6.6.0
Description An issue exists in the OAuth2 implementation of Corezoid that allows for account takeover. The vulnerability is due to an open redirect within the redirect uri parameter. This allows attackers to intercept authorization codes and gain unauthorized access to victim accounts.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-55017

Affected Products

Corezoid