Open Source Research Tool Vulnerability in Taguette by Remram44
CVE-2025-67502

5.4MEDIUM

Key Information:

Vendor

Remram44

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-67502?

Taguette, an open-source qualitative research tool, has a vulnerability in versions 1.5.1 and earlier where attackers can exploit the user-controlled 'next' parameter. This flaw permits unauthorized HTTP redirects to arbitrary external websites post-authentication, enabling phishing attacks. Users, believing they are interacting with the legitimate Taguette platform, may unwittingly provide sensitive information to malicious sites designed to compromise their credentials or deliver malware. The issue has been addressed in version 1.5.2 of the application.

Affected Version(s)

taguette < 1.5.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67502 : Open Source Research Tool Vulnerability in Taguette by Remram44