First published: Thu May 08 2025(Updated: )
Rapid7 Corporate Website prior to May 2nd 2025, suffered from a URL Redirection to Untrusted Site ('Open Redirect') vulnerability whereby, due to misconfigured headers, an attacker could successfully redirect users to a malicious site of their control. This vulnerability has been fixed as of May 2nd 2025.
Credit: cve@rapid7.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rapid7 Rapid7 Corporate Website | <May 2nd 2025 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4132 is classified as a medium severity vulnerability due to its potential for exploitation via an open redirect.
To fix CVE-2025-4132, ensure that all URL redirection functionalities are properly configured and validate redirected URLs against a whitelist of trusted domains.
CVE-2025-4132 can lead users to malicious websites, potentially resulting in phishing attacks or malware infections.
CVE-2025-4132 was disclosed after May 2nd, 2025, when the vulnerability was identified in the Rapid7 Corporate Website.
All versions of Rapid7 Corporate Website prior to May 2nd, 2025, are affected by CVE-2025-4132.