CVE-2022-26954

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
20/10/2022
Last modified:
08/05/2025

Description

Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nopcommerce:nopcommerce:*:*:*:*:*:*:*:* 4.10 (including) 4.50.2 (excluding)