Volo.Abp.Account.Web
Package Description
Activity
- Latest release
- 14h ago
- Total releases
- 294
- Cadence
- ~7 days
- Last 12 months
- 41
Details
- License
- unknown
- First release
- Jun 27, 2018
| Version | Released | |
|---|---|---|
10.6.1
patch
|
10.6.1
patch
Dependencies (5)
|
|
10.7.0-rc.4
pre
|
10.7.0-rc.4
pre
Dependencies (5)
|
|
10.7.0-rc.3
pre
|
10.7.0-rc.3
pre
Dependencies (5)
|
|
10.7.0-rc.2
pre
|
10.7.0-rc.2
pre
Dependencies (5)
|
|
10.7.0-rc.1
pre
|
10.7.0-rc.1
pre
Dependencies (5)
|
|
10.6.0
minor
|
10.6.0
minor
Dependencies (5)
|
|
10.6.0-rc.3
pre
|
10.6.0-rc.3
pre
Dependencies (5)
|
|
10.6.0-rc.2
pre
|
10.6.0-rc.2
pre
Dependencies (5)
|
|
10.6.0-rc.1
pre
|
10.6.0-rc.1
pre
Dependencies (5)
|
|
10.5.0
minor
|
10.5.0
minor
Dependencies (5)
|
|
10.5.0-rc.4
pre
|
10.5.0-rc.4
pre
Dependencies (5)
|
|
10.5.0-rc.3
pre
|
10.5.0-rc.3
pre
Dependencies (5)
|
|
10.5.0-rc.2
pre
|
10.5.0-rc.2
pre
Dependencies (5)
|
|
10.5.0-rc.1
pre
|
10.5.0-rc.1
pre
Dependencies (5)
|
|
10.4.1
patch
|
10.4.1
patch
Dependencies (5)
|
|
10.4.0
minor
|
10.4.0
minor
Dependencies (5)
|
|
10.4.0-rc.2
pre
|
10.4.0-rc.2
pre
Dependencies (5)
|
|
10.4.0-rc.1
pre
|
10.4.0-rc.1
pre
Dependencies (5)
|
|
10.3.0
minor
|
10.3.0
minor
Dependencies (5)
|
|
10.2.1
patch
|
10.2.1
patch
Dependencies (5)
|
|
10.3.0-rc.2
pre
|
10.3.0-rc.2
pre
Dependencies (5)
|
|
10.3.0-rc.1
pre
|
10.3.0-rc.1
pre
Dependencies (5)
|
|
10.2.0
minor
|
10.2.0
minor
Dependencies (5)
|
|
10.2.0-rc.4
pre
|
10.2.0-rc.4
pre
Dependencies (5)
|
|
10.2.0-rc.3
pre
|
10.2.0-rc.3
pre
Dependencies (5)
|
|
10.2.0-rc.2
pre
|
10.2.0-rc.2
pre
Dependencies (5)
|
|
10.1.1
patch
|
10.1.1
patch
Dependencies (5)
|
|
10.2.0-rc.1
pre
|
10.2.0-rc.1
pre
Dependencies (5)
|
|
10.1.0
minor
|
10.1.0
minor
Dependencies (5)
|
|
10.1.0-rc.3
pre
|
10.1.0-rc.3
pre
Dependencies (5)
|
|
10.0.3
patch
|
10.0.3
patch
Dependencies (5)
|
|
10.1.0-rc.2
pre
|
10.1.0-rc.2
pre
Dependencies (5)
|
|
10.1.0-rc.1
pre
|
10.1.0-rc.1
pre
Dependencies (5)
|
|
10.0.2
patch
|
10.0.2
patch
Dependencies (5)
|
|
9.3.7
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.7
patch
Dependencies (5)
|
|
10.0.1
patch
|
10.0.1
patch
Dependencies (5)
|
|
10.0.0
major
|
10.0.0
major
Dependencies (5)
|
|
10.0.0-rc.3
pre
|
10.0.0-rc.3
pre
Dependencies (5)
|
|
10.0.0-rc.2
pre
|
10.0.0-rc.2
pre
Dependencies (5)
|
|
9.3.6
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.6
patch
Dependencies (5)
|
|
10.0.0-rc.1
pre
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
10.0.0-rc.1
pre
Dependencies (5)
|
|
9.3.5
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.5
patch
Dependencies (5)
|
|
9.3.4
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.4
patch
Dependencies (5)
|
|
9.3.3
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.3
patch
Dependencies (5)
|
|
9.3.2
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.2
patch
Dependencies (5)
|
|
9.2.4
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.2.4
patch
Dependencies (5)
|
|
9.3.1
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.1
patch
Dependencies (5)
|
|
9.3.0
minor
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.0
minor
Dependencies (5)
|
|
9.3.0-rc.4
pre
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.3.0-rc.4
pre
Dependencies (5)
|
|
9.2.3
patch
1 CVE
CVE-2025-65581
GHSA-vfm5-cr22-jg3m
Dec 16, 2025
ABP Account Module has an Open Redirect through Improper validation in its register function
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improper validation of the returnUrl parameter in the register function allows an attacker to redirect users to arbitrary external domains. Affected versions
5.1.0
5.1.1
5.1.2
5.1.3
5.1.4
5.2.0
5.2.1
5.2.2
5.3.0
5.3.1
5.3.2
5.3.3
+ 73 more Show less
5.3.4
5.3.5
6.0.0
6.0.1
6.0.2
6.0.3
7.0.0
7.0.1
7.0.2
7.0.3
7.1.0
7.1.1
7.2.1
7.2.2
7.2.3
7.3.0
7.3.1
7.3.2
7.3.3
7.4.0
7.4.1
7.4.2
7.4.3
7.4.4
7.4.5
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.0.6
8.1.0
8.1.1
8.1.2
8.1.3
8.1.4
8.1.5
8.2.0
8.2.1
8.2.2
8.2.3
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
9.0.0
9.0.1
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.1.0
9.1.1
9.1.2
9.1.3
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.3.0
9.3.1
9.3.2
9.3.3
9.3.4
9.3.5
9.3.6
9.3.7
Fixed in
10.0.0-rc.2
References Updated Dec 16, 2025 · Source: OSV.dev |
9.2.3
patch
Dependencies (5)
|