CVE-2025-64115

⚪ Do wiadomości

Otwarte przekierowanie w Movary umożliwia phishing poprzez złośliwe linki.

CVSS
6.1
EPSS
0.3%
Exploit
poc
Vendor
leepeuker
Opis źródłowy (NVD)

Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in multiple settings endpoints, allowing a crafted link to cause an open redirect to an attacker-controlled site and facilitate phishing. This vulnerability is fixed in 0.69.0.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-30 18:15:33 UTC
Ostatnia modyfikacja (NVD)2026-10-07 22:10:00 UTC
Referencje