CVE-2022-25295: Open Redirect

Published Sep 11, 2022
·
Updated

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

Affected Software

1 affected component
Getgophish Gophish<0.12.0

Event History

Sep 11, 2022
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2022-25295?

The severity of CVE-2022-25295 is medium with a CVSS score of 5.4.

2

How does CVE-2022-25295 affect the affected software?

CVE-2022-25295 affects the package github.com/gophish/gophish before version 0.12.0.

3

What is the vulnerability in CVE-2022-25295?

The vulnerability in CVE-2022-25295 is an Open Redirect vulnerability.

4

How can the Open Redirect vulnerability in CVE-2022-25295 be exploited?

The Open Redirect vulnerability in CVE-2022-25295 can be exploited by manipulating the 'next' query parameter to redirect users to a malicious URL.

5

How can I fix CVE-2022-25295?

To fix CVE-2022-25295, upgrade to version 0.12.0 or later of the github.com/gophish/gophish package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203