PT-2025-53299 · Unknown · Blitz Panel
Hexer365
·
Published
2025-12-24
·
Updated
2025-12-27
·
CVE-2025-60935
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Blitz Panel version 1.17.0
Description
An open redirect issue exists in the login functionality of Blitz Panel. The issue is located in the
/login endpoint and involves the next url parameter. Successful exploitation could allow an attacker to redirect a user to a malicious domain, potentially leading to phishing or token theft after authentication.Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting or validating the
next url parameter in the /login endpoint to prevent redirection to untrusted domains.Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blitz Panel