Zurück zur CVE-Übersicht
CVE-2026-90453
NONERisk Signal Score0/100 — NIEDRIG
Erwähnungen (letzte 60 Tage)
Artikel
EPSS-Score
0.4%
Exploit-Wahrscheinlichkeit (30 Tage)
Beschreibung
A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's browser to be redirected to an arbitrary external destination after completing an upload.