Web / CMS
Spoofing
Unvalidated redirection vulnerability in Fuge CMS v1.0
Unvalidated redirection vulnerability in Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is
.png)
Overview
Unvalidated redirection vulnerability in Fuge CMS v1.0
The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is taking the nextUrl parameter as a user input and passing it without any validation. in next lines this nextUrl parameter is being used for redirection.
Vulnerability details
Unvalidated redirection vulnerability in Fuge CMS v1.0 The vulnerability exists in the file https://github.com/fuge/cms/blob/master/src/foo/cms/action/member/RegisterAct.java where application is taking the nextUrl parameter as a user input and passing it
Disclosure timeline
2023-06-06 Reported On
2023-07-31 Made Public On
Fixed On: Not Fixed
References
2026-06-17 (NVD record)
Credits
Akshat Singhal
















