Vulnerability Description
An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the login endpoint and could lead to phishing or token theft after successful authentication.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Returnfi | Blitz | 1.17.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/HEXER365/2e866b47d56585e1e59e7c16bf4b4db7Third Party Advisory
- https://github.com/ReturnFI/BlitzProduct
FAQ
What is CVE-2025-60935?
CVE-2025-60935 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malicious domains via a crafted URL. This issue affects the next_url parameter in the ...
How severe is CVE-2025-60935?
CVE-2025-60935 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-60935?
Check the references section above for vendor advisories and patch information. Affected products include: Returnfi Blitz.