
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14692 is an open redirect vulnerability (CWE-601) in Mayan EDMS, an open-source document management system. The flaw exists in the /authentication/ endpoint and allows unauthenticated remote attackers to redirect users to arbitrary external websites by manipulating URL fragment or next parameters. It affects Mayan EDMS versions prior to 4.10.2 (specifically: < 4.6.12, >= 4.7.0 < 4.7.8, >= 4.8.0 < 4.8.10, >= 4.9.0 < 4.9.7, and >= 4.10.0 < 4.10.2). The vulnerability was published on December 14–15, 2025, with a CVSS v3.1 base score of 6.1 (Medium) per NVD and a CVSS v4.0 score of 2.1 (Low) per the CNA (GitHub Advisory, NVD).
The root cause is insecure client-side JavaScript handling of the URL hash fragment (window.location.hash) within Mayan EDMS's navigation template (CWE-601). The vulnerable code constructs a redirect URL by appending window.location.pathname and window.location.search to the hash fragment without any sanitization or validation, then assigns the result directly to window.location. Multiple authentication-related endpoints are affected, including /authentication/login/, /authentication/password/reset/, and their variants with next parameters. An attacker can craft a URL such as http://target/authentication/login/#https://evil.com to trigger an automatic redirect to an attacker-controlled site upon page load, requiring no authentication (GitHub PoC, GitHub Advisory).
Successful exploitation enables phishing attacks by silently redirecting users visiting legitimate Mayan EDMS authentication pages to attacker-controlled sites such as credential harvesting pages or malware distribution portals. The vulnerability has no direct impact on availability or server-side confidentiality, but poses a meaningful integrity and social engineering risk — particularly for organizations where users trust the EDMS domain. Lateral movement is not directly facilitated, but stolen credentials obtained via phishing could enable subsequent unauthorized access to the document management system and its stored content (GitHub Advisory, Feedly).
A public proof-of-concept exploit is available on GitHub, published by researcher ionutluca888, demonstrating the open redirect across multiple authentication endpoints (GitHub PoC). The vulnerability requires no authentication and only passive user interaction (a victim clicking a crafted link), making it straightforward to weaponize for phishing campaigns. The EPSS score is approximately 0.085–0.097%, indicating a low but non-negligible probability of exploitation in the wild. There is no evidence of active in-the-wild exploitation or threat actor attribution at this time, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, Feedly).
/authentication/login/.http://<target>/authentication/login/#https://evil.com or with a next parameter variant such as http://<target>/authentication/login/?next=/home/#https://evil.com.window.location.hash (attacker-controlled) and assigns it to window.location, immediately redirecting the browser to the attacker's site without any warning./authentication/login/, /authentication/password/reset/, or their ?next= variants containing a URL fragment (#) with an external domain (e.g., #https://evil.com); outbound redirects (HTTP 3xx or JavaScript-based) from the Mayan EDMS server to unexpected external domains.next parameter; repeated access from diverse source IPs to authentication endpoints with suspicious hash values.The vendor has released patched versions addressing this vulnerability across all supported branches: 4.10.2, 4.9.7, 4.8.10, 4.7.8, and 4.6.12. Upgrading to the appropriate patched version is the recommended remediation. The vendor confirmed the fix in version 4.10.2 and indicated that backports for older versions were in progress via their CI pipelines. No configuration-based workaround is documented; upgrading is the only reliable mitigation. Organizations should also educate users about phishing risks associated with authentication redirect links (GitHub Advisory, Mayan Release Notes).
The vulnerability received limited but notable coverage, including a post on Bluesky via the CVE tracking account and coverage by security aggregators such as Vulners, CIRCL, and INCIBE-CERT. The infinitsec.net blog published a dedicated write-up on the vulnerability shortly after disclosure. No major vendor statements beyond the Mayan EDMS release notes have been identified, and community reaction has been modest given the medium/low severity rating.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."