SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.
History

Thu, 19 Feb 2026 15:30:00 +0000

Type Values Removed Values Added
Description SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a malicious URL that, when visited by a victim, redirects them to an arbitrary external site after login. This vulnerability only affects sites where the login page has been overridden to function in AJAX mode. It is not mitigated by the SPIP security screen.
Title SPIP < 4.4.5 Open Redirect via Login Form
First Time appeared Spip
Spip spip
Weaknesses CWE-601
CPEs cpe:2.3:a:spip:spip:*:*:*:*:*:*:*:*
Vendors & Products Spip
Spip spip
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-19T17:35:57.666Z

Reserved: 2026-02-19T03:00:22.782Z

Link: CVE-2025-71244

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-19T16:27:12.507

Modified: 2026-02-19T16:27:12.507

Link: CVE-2025-71244

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.