Web Application Vulnerability in DiracX-Web by DIRACGrid
CVE-2025-54066
4.7MEDIUM
What is CVE-2025-54066?
DiracX-Web, a web application from DIRACGrid, has a vulnerability that allows attackers to craft requests leading to arbitrary URL redirection. This flaw lies within the redirect
field during user authentication. Since the application does not verify the input URI, an attacker can exploit this to redirect authenticated users to malicious websites, potentially leading to phishing attempts. By combining this issue with parameter pollution techniques, attackers can effectively hide their malicious URLs, enhancing the risk of credential theft. The vulnerability has been addressed in version 0.1.0-a8.
Affected Version(s)
diracx-web < 0.1.0-a8