VulnerabilityAnalyzed
CVE-2025-34504
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter.
MEDIUM 5.3EPSS 0.32%
Does this matter?
Lower severity and a low EPSS score (0.32%). Track it; it rarely justifies an emergency change on its own.
Description
KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.
- CVSS 4.0
- 5.3 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.32% probability · 25th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- kodcloud/kodexplorer
- Source
- disclosure@vulncheck.com
References
- https://github.com/kalcaddle/KodExplorer/releases/tag/4.52Release Notes
- https://kodcloud.com/Product
- https://www.exploit-db.com/exploits/52245Exploit, Third Party Advisory, VDB Entry
- https://www.vulncheck.com/advisories/kodexplorer-open-redirect-vulnerability-via-user-login-endpointThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.