← Vulnerability feed

Vulnerability record · CVE-2022-25295 · published 11 September 2022

CVE-2022-25295: Getgophish gophish open redirect vulnerability

Getgophish · Gophish

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

5.4 CVSS 3.1 Medium EPSS 0.67% · top 50.0% CWE-601 · Open redirect
5.4CVSS 3.1 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

This affects the package github.com/gophish/gophish before 0.12.0. The Open Redirect vulnerability exists in the next query parameter. The application uses url.Parse(r.FormValue("next")) to extract path and eventually redirect user to a relative URL, but if next parameter starts with multiple backslashes like \\\\\\example.com, browser will redirect user to http://example.com.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25295 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-24707Getgophish gophish csv injection vulnerabilityGophish before 0.11.0 allows the creation of CSV sheets that contain malicious content.EPSS 1.3%7.6CVE-2025-70963Getgophish gophish information exposure vulnerabilityGophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly inside the r…EPSS 0.28%7.5CVE-2022-45003Getgophish gophish uncontrolled resource consumption vulnerabilityGophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.EPSS 1.0%7.5CVE-2020-24713Getgophish gophish insufficient session expiration vulnerabilityGophish through 0.10.1 does not invalidate the gophish cookie upon logout.EPSS 1.2%6.5CVE-2020-24711Getgophish gophish clickjacking vulnerabilityThe Reset button on the Account Settings page in Gophish before 0.11.0 allows attackers to cause a denial of service via a clickjacking attackEPSS 1.6%6.1CVE-2024-2211Getgophish gophish cross-site scripting vulnerabilityCross-Site Scripting stored vulnerability in Gophish affecting version 0.12.1. This vulnerability could allow an attacker to store a malicious JavaSc…EPSS 0.29%6.1CVE-2022-45004Getgophish gophish cross-site scripting vulnerabilityGophish through 0.12.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted landing page.EPSS 0.60%5.4CVE-2020-24708Getgophish gophish cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in Gophish before 0.11.0 via the Host field on the send profile form.EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2022-25295), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.