CVE-2025-4132: Unvalidated Redirect Vulnerability on Rapid7.com
Published May 8, 2025
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
Rapid7 Corporate Website<May 2nd 2025
Event History
May 8, 2025
CVE Published
via MITRE·03:10 PM
Rejected
via MITRE·03:10 PM
Data Sourced
via NVD·04:15 PM
Description
May 12, 2025
Rejected
via MITRE·08:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-4132?
CVE-2025-4132 is classified as a medium severity vulnerability due to its potential for exploitation via an open redirect.
2
How do I fix CVE-2025-4132?
To fix CVE-2025-4132, ensure that all URL redirection functionalities are properly configured and validate redirected URLs against a whitelist of trusted domains.
3
What impact does CVE-2025-4132 have on users?
CVE-2025-4132 can lead users to malicious websites, potentially resulting in phishing attacks or malware infections.
4
When was CVE-2025-4132 disclosed?
CVE-2025-4132 was disclosed after May 2nd, 2025, when the vulnerability was identified in the Rapid7 Corporate Website.
5
Which versions of Rapid7 Corporate Website are affected by CVE-2025-4132?
All versions of Rapid7 Corporate Website prior to May 2nd, 2025, are affected by CVE-2025-4132.