Security Advisory

CVE-2025-65581

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-16 00:00:00
Last updated 2025-12-16 19:14:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.