Sanluan PublicCMS Open Redirect Vulnerability in PDF.js Viewer

Vulnerability

An open redirect vulnerability has been identified in Sanluan PublicCMS versions through 5.202506.a. The issue arises in the PDF.js viewer file, where the 'file' parameter can be manipulated to redirect users to external sites without proper security checks. This vulnerability can be exploited remotely, particularly on iPhone, iPad, or iPod devices.

Impact

Exploitation of this vulnerability leads to an open redirect, allowing attackers to redirect users to malicious websites, potentially facilitating phishing attacks.

Reproduction

To reproduce this vulnerability, access the PDF.js viewer file and include a 'file' parameter in the URL query string. If the request is made from an iPhone, iPad, or iPod, the user will be redirected to the URL specified in the 'file' parameter.

Remediation

Users are advised to update to the patched version of Sanluan PublicCMS. The patch is available on the Sanluan PublicCMS GitHub repository.

Added: Jul 22, 2025, 4:19 AM
Updated: Jul 22, 2025, 4:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.7
remediation
7.7
relevance
0.3
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.