CVE-2025-65581: Volosoft Abp
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
Affected products
- Volosoft Abp: from 5.1.0, before 10.0.0 (fixed in 10.0.0); version 10.0.0 only
Published 2025-12-16. Last modified 2026-06-17.