Security Advisory

CVE-2026-73671

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-13 16:00:13
Last updated 2026-08-14 16:52:45
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the url parameter supplied via GET or POST is passed directly to the Location header without domain allowlist, scheme validation, or relative path enforcement. Attackers can craft a malicious logout URL containing an arbitrary external domain or javascript: URI scheme to redirect authenticated users to attacker-controlled phishing pages after session destruction, enabling credential theft and OAuth redirect abuse.