Open Redirection Vulnerability in Mautic by Mautic
CVE-2025-5256
5.4MEDIUM
What is CVE-2025-5256?
This vulnerability involves an Open Redirection flaw in Mautic's user unlocking endpoint, where an attacker can manipulate the returnUrl parameter. Due to improper validation, this allows for redirection of users to malicious external sites, potentially leading to phishing attempts or exploit kit dissemination. To mitigate this risk, users must update Mautic to versions that ensure proper validation and sanitization of the returnUrl parameter to restrict redirects to only trusted URLs or whitelisted domains.
Affected Version(s)
Mautic > 1.0.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tomasz Kowalczyk
Tomasz Kowalczyk
Nick Vanpraet
Patryk Gruszka