CVE-2025-71244: SPIP < 4.4.5 Open Redirect via Login Form
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71244?
The severity of CVE-2025-71244 is classified as a medium risk due to the potential for phishing and exploitation via open redirects.
How do I fix CVE-2025-71244?
To fix CVE-2025-71244, update your SPIP installation to version 4.4.5 or later, or 4.3.9 if using that branch.
What type of vulnerability is CVE-2025-71244?
CVE-2025-71244 is an open redirect vulnerability that allows attackers to redirect users to arbitrary external sites.
Which versions of SPIP are affected by CVE-2025-71244?
CVE-2025-71244 affects SPIP versions prior to 4.4.5 and 4.3.9.
What can attackers do with CVE-2025-71244?
Attackers can use CVE-2025-71244 to perform phishing attacks by redirecting users to malicious sites after login.