Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users to phishing sites or other malicious destinations via “/%2f%2f<MALICIOUS_DOMAIN>”.

Project Subscriptions

Vendors Products
Molgenis Subscribe
Advisories

No advisories yet.

Fixes

Solution

The MOLGENIS team has resolved the vulnerability reported in version 13.19.4.


Workaround

No workaround given by the vendor.

History

Fri, 24 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Molgenis
Molgenis emx2
Vendors & Products Molgenis
Molgenis emx2

Thu, 23 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 11:30:00 +0000

Type Values Removed Values Added
Description Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users to phishing sites or other malicious destinations via “/%2f%2f<MALICIOUS_DOMAIN>”.
Title Open redirection vulnerability in MOLGENIS EMX2
Weaknesses CWE-601
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-10-23T14:31:10.279Z

Reserved: 2025-09-12T10:35:07.568Z

Link: CVE-2025-10355

cve-icon Vulnrichment

Updated: 2025-10-23T14:31:05.816Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-23T12:15:29.840

Modified: 2025-10-27T13:20:33.350

Link: CVE-2025-10355

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-10-24T10:16:54Z

Weaknesses