Bunkerity Bunker Web Open Redirect Vulnerability

Vulnerability

A URL redirection vulnerability allowing phishing attacks has been identified in Bunkerity Bunker Web version 1.6.2 on Linux. This open redirect issue occurs on the '/loading' endpoint, which accepts a 'next' parameter for post-login redirection. The vulnerability enables authenticated users to be redirected to arbitrary external sites, potentially leading to phishing scenarios.

Impact

Exploitation of this vulnerability could result in unauthorized redirection of users to malicious websites, increasing the risk of phishing attacks.

Reproduction

To reproduce this vulnerability, log into the Bunker Web application. After logging in, access the '/loading' endpoint with a 'next' parameter that includes a protocol-relative URL pointing to an external site. This will trigger the redirection to the specified site. Alternatively, for an unauthenticated user, the same 'next' parameter can be used with the login request, which will redirect them to the external site after logging in.

Added: Aug 15, 2025, 4:17 PM
Updated: Aug 15, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
1.0
exploitability
7.7
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.