CVE-2025-64115
⚪ Do wiadomości
Otwarte przekierowanie w Movary umożliwia phishing poprzez złośliwe linki.
CVSS
6.1
EPSS
0.3%
Exploit
poc
Vendor
leepeuker
Opis źródłowy (NVD)
Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in multiple settings endpoints, allowing a crafted link to cause an open redirect to an attacker-controlled site and facilitate phishing. This vulnerability is fixed in 0.69.0.
exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-10-30 18:15:33 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 22:10:00 UTC |
Referencje
- https://github.com/leepeuker/movary/commit/716f703b4464ffdb0365c406f3660d275495769f ([email protected]) [Patch]
- https://github.com/leepeuker/movary/pull/713 ([email protected]) [Issue Tracking]
- https://github.com/leepeuker/movary/security/advisories/GHSA-pm58-79jw-q79f ([email protected]) [Exploit, Third Party Advisory]