CVE-2020-24550: Episerver Find

Medium severity, CVSS 6.1. EPSS: 4.7% chance of exploitation in the next 30 days.

An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL.

Affected products

  • Episerver Find: before 13.2.7 (fixed in 13.2.7)

Published 2021-03-31. Last modified 2026-06-17.