Web / CMS
Spoofing
Unvalidated open redirection Fuge CMS v1.0
Unvalidated open redirection Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking
.png)
Overview
Unvalidated open redirection Fuge CMS v1.0
The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking RETURN_URL parameter as a user input and passing it without any validation. in next lines this returnUrl parameter is being used for redirection.
Vulnerability details
Unvalidated open redirection Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/core/action/front/ProcessAct.java where application is taking RETURN_URL parameter as a user input and passing it without any
Disclosure timeline
2023-06-06 Reported On
2023-07-31 Made Public On
Fixed On: Not Fixed
References
2026-06-17 (NVD record)
Credits
Akshat Singhal
















