Saurus CMS Unauthenticated Open Redirect via logout url parameter
Published Aug 13, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.31%
Description
Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can craft a malicious logout URL containing an arbitrary external domain or javascript: URI scheme to redirect authenticated users to attacker-controlled phishing pages after session destruction, enabling credential theft and OAuth redirect abuse.
Affected products
-
- Version 0StatusaffectedConstraints<=d886e5b
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Saurus | Saurus CMS Community Edition | affected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/DevVaibhav07/VULN-POC/blob/main/Saurus_OpenRedirect.md exploittechnical-description
- https://github.com/sauruscms/Saurus-CMS-Community-Edition product
- https://www.vulncheck.com/advisories/saurus-cms-unauthenticated-open-redirect-via-logout-url-parameter third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/DevVaibhav07/VULN-POC/blob/main/Saurus_OpenRedirect.md | exploittechnical-description | |
| https://github.com/sauruscms/Saurus-CMS-Community-Edition | product | |
| https://www.vulncheck.com/advisories/saurus-cms-unauthenticated-open-redirect-via-logout-url-parameter | third-party-advisory |
Change history (0)
No recorded changes yet.