Web Application Vulnerability in DiracX-Web by DIRACGrid
CVE-2025-54066

4.7MEDIUM

Key Information:

Vendor

Diracgrid

Vendor
CVE Published:
17 July 2025

What is CVE-2025-54066?

DiracX-Web, a web application from DIRACGrid, has a vulnerability that allows attackers to craft requests leading to arbitrary URL redirection. This flaw lies within the redirect field during user authentication. Since the application does not verify the input URI, an attacker can exploit this to redirect authenticated users to malicious websites, potentially leading to phishing attempts. By combining this issue with parameter pollution techniques, attackers can effectively hide their malicious URLs, enhancing the risk of credential theft. The vulnerability has been addressed in version 0.1.0-a8.

Affected Version(s)

diracx-web < 0.1.0-a8

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54066 : Web Application Vulnerability in DiracX-Web by DIRACGrid