Open Source Research Tool Vulnerability in Taguette by Remram44
CVE-2025-67502
5.4MEDIUM
What is CVE-2025-67502?
Taguette, an open-source qualitative research tool, has a vulnerability in versions 1.5.1 and earlier where attackers can exploit the user-controlled 'next' parameter. This flaw permits unauthorized HTTP redirects to arbitrary external websites post-authentication, enabling phishing attacks. Users, believing they are interacting with the legitimate Taguette platform, may unwittingly provide sensitive information to malicious sites designed to compromise their credentials or deliver malware. The issue has been addressed in version 1.5.2 of the application.
Affected Version(s)
taguette < 1.5.2
