← Vulnerability feed

Vulnerability record · CVE-2024-55452 · published 16 December 2024

CVE-2024-55452: Ujcms open redirect vulnerability

UUjcms · Ujcms

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage.

5.4 CVSS 3.1 Medium EPSS 0.27% · top 83.1% CWE-601 · Open redirect
5.4CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, attacker-controlled webpage. When an authenticated user clicks on the malicious block item, they are redirected to the arbitrary untrusted domains, where sensitive tokens, such as JSON Web Tokens, can be stolen via a crafted webpage.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-55452 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51350Ujcms authentication bypass by spoofing vulnerabilityA spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-…EPSS 1.3%9.8CVE-2023-34747Ujcms unrestricted file upload vulnerabilityFile upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.EPSS 20%9.8CVE-2023-34865Ujcms path traversal vulnerabilityDirectory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.EPSS 1.2%7.5CVE-2023-34878Ujcms observable discrepancy vulnerabilityAn issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/downl…EPSS 0.70%6.5CVE-2023-3231Ujcms information exposure vulnerabilityA vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa…EPSS 0.82%6.3CVE-2024-12483Ujcms improper authorization vulnerabilityA vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…EPSS 3.6%6.1CVE-2023-24369Ujcms cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload …EPSS 0.43%5.4CVE-2023-51806Ujcms unrestricted file upload vulnerabilityFile Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.EPSS 0.55%

Source: NIST National Vulnerability Database (record CVE-2024-55452), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.