PT-2025-51767 · Volosoft · Appframework

Published

2025-12-16

·

Updated

2025-12-21

·

CVE-2025-65581

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Volosoft ABP Framework versions 5.1.0 through 9.9.9-rc.2
Description An open redirect issue exists within the Account module. Insufficient validation of the returnUrl parameter in the register function enables an attacker to redirect users to external websites. The vulnerability affects the application's ability to securely handle user redirection after registration.
Recommendations Volosoft ABP Framework versions 5.1.0 through 9.9.9-rc.2: Ensure proper validation of the returnUrl parameter in the register function to prevent redirection to arbitrary external domains.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-65581
GHSA-VFM5-CR22-JG3M

Affected Products

Appframework