← back
CVE-2025-55751

OnboardLite Open Redirect Endpoint

CVSS 5.1 MEDIUMEPSS 0.3%CWE-601
OnboardLite is the result of the Influx Initiative, our vision for an improved student organization lifecycle at the University of Central Florida. An attacker can craft a link to the trusted application that, when visited, redirects the user to a malicious external site. This enables phishing, credential theft, malware delivery, and trust abuse. Any version with commit hash 6cca19e or later implements jwt signing for the redirect url parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Affected products
HackUCF · OnboardLite

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →