dataCycle-CORE Password Reset and Confirmation Flow URL Redirection Vulnerability

Vulnerability

A vulnerability exists in dataCycle-CORE versions prior to 25.07.3, allowing low-privileged authenticated API users to manipulate `forwardToUrl` and `redirectUrl` values during password reset or confirmation processes. These values are sent in the outgoing emails without any host allowlisting. This vulnerability creates two related abuse paths: first, an attacker can send a victim a password reset or confirmation link with a token attached, directing them to an attacker-controlled `forwardToUrl`; second, after a legitimate password reset, the victim's browser is redirected to an attacker-controlled `redirectUrl`. This could be exploited for phishing, token capture, confirmation hijacking, or redirecting a victim from a trusted email to an attacker-controlled domain.

Impact

Exploitation of this vulnerability could lead to phishing attacks, unauthorized token capture, hijacking of confirmation processes, or redirecting victims from a trusted email to an attacker-controlled domain.

Remediation

Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.

Added: Jul 21, 2026, 12:43 AM
Updated: Jul 21, 2026, 12:43 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.9
exploitability
4.8
remediation
0.0
relevance
9.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.