datacycle-engine dataCycle-CORE
- <= 25.07.3
A vulnerability exists in dataCycle-CORE versions prior to 25.07.3, allowing low-privileged authenticated API users to manipulate `forwardToUrl` and `redirectUrl` values during password reset or confirmation processes. These values are sent in the outgoing emails without any host allowlisting. This vulnerability creates two related abuse paths: first, an attacker can send a victim a password reset or confirmation link with a token attached, directing them to an attacker-controlled `forwardToUrl`; second, after a legitimate password reset, the victim's browser is redirected to an attacker-controlled `redirectUrl`. This could be exploited for phishing, token capture, confirmation hijacking, or redirecting a victim from a trusted email to an attacker-controlled domain.
Exploitation of this vulnerability could lead to phishing attacks, unauthorized token capture, hijacking of confirmation processes, or redirecting victims from a trusted email to an attacker-controlled domain.
Users can upgrade to dataCycle-CORE version 26.06.08 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.