MEDIUM5.3
GHSA-vfm5-cr22-jg3m
ABP Account Module has an Open Redirect through Improper validation in its register function
Quick fix
GHSA-vfm5-cr22-jg3m — Volo.Abp.Account.Web: upgrade to the fixed version with the command below.
dotnet add package Volo.Abp.Account.Web --version 10.0.0-rc.2Details
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/Volo.Abp.Account.Web
Introduced in:
5.1.0Fixed in: 10.0.0-rc.2Fix
dotnet add package Volo.Abp.Account.Web --version 10.0.0-rc.2