OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft, malware delivery, and trust abuse. Any version with commit hash 6cca19e or later implements jwt signing for the redirect url parameter.
Metrics
Affected Vendors & Products
References
History
Wed, 20 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft, malware delivery, and trust abuse. Any version with commit hash 6cca19e or later implements jwt signing for the redirect url parameter. | |
Title | OnboardLite Open Redirect Endpoint | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-08-20T15:31:48.496Z
Updated: 2025-08-20T18:07:13.067Z
Reserved: 2025-08-14T22:31:17.685Z
Link: CVE-2025-55751

Updated: 2025-08-20T18:06:33.408Z

Status : Received
Published: 2025-08-20T16:15:43.313
Modified: 2025-08-20T16:15:43.313
Link: CVE-2025-55751

No data.