CVE-2025-46826

Severity CVSS v4.0:
LOW
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
07/05/2025
Last modified:
08/05/2025

Description

insa-auth is an authentication server for INSA Rouen. A minor issue allowed third-party websites to access the server's secondary authentication bridge, potentially revealing basic student information (name and number). However, the issue posed minimal risk, was never exploited, and had limited impact. A fix was implemented promptly on May 3, 2025.