SPIP < 4.4.5 Open Redirect via Login Form
Vulnerability Description
SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-71244
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- SPIP security team
References
More from SPIP
View All →Affected Vendor
SPIP
View all reports →