Open Redirection Vulnerability in Mautic by Mautic
CVE-2025-5256

5.4MEDIUM

Key Information:

Vendor

Mautic

Status
Vendor
CVE Published:
28 May 2025

What is CVE-2025-5256?

This vulnerability involves an Open Redirection flaw in Mautic's user unlocking endpoint, where an attacker can manipulate the returnUrl parameter. Due to improper validation, this allows for redirection of users to malicious external sites, potentially leading to phishing attempts or exploit kit dissemination. To mitigate this risk, users must update Mautic to versions that ensure proper validation and sanitization of the returnUrl parameter to restrict redirects to only trusted URLs or whitelisted domains.

Affected Version(s)

Mautic > 1.0.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomasz Kowalczyk
Tomasz Kowalczyk
Nick Vanpraet
Patryk Gruszka
.