CVE-2025-64116

Severity CVSS v4.0:
MEDIUM
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
30/10/2025
Last modified:
08/12/2025

Description

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:* 0.69.0 (excluding)