CVE-2025-6701: Xuxueli xxl-sso doLogin redirect
A vulnerability, which was classified as problematic, has been found in Xuxueli xxl-sso 1.1.0. This issue affects some unknown processing of the file /xxl-sso-server/doLogin. The manipulation of the argument redirecturl leads to open redirect. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6701?
CVE-2025-6701 is classified as a problematic vulnerability due to its potential for open redirection attacks.
How do I fix CVE-2025-6701?
To fix CVE-2025-6701, ensure that the redirect_url parameter is properly validated and sanitized before use.
What kind of vulnerability is CVE-2025-6701?
CVE-2025-6701 is an open redirect vulnerability affecting the Xuxueli xxl-sso application.
What could an attacker achieve with CVE-2025-6701?
An attacker could leverage CVE-2025-6701 to execute phishing attacks by redirecting users to malicious sites.
Which software is affected by CVE-2025-6701?
CVE-2025-6701 affects the Xuxueli xxl-sso version 1.1.0.