The application contains an insecure 'redirectToUrl'...
Critical severity
Unreviewed
Published
Nov 27, 2025
to the GitHub Advisory Database
•
Updated Nov 27, 2025
Description
Published by the National Vulnerability Database
Nov 27, 2025
Published to the GitHub Advisory Database
Nov 27, 2025
Last updated
Nov 27, 2025
The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary code execution.
This issue was fixed in version wu#2016.1.5513#0#20251014_113353
References