CVE-2025-0970 | Zenvia Movidesk up to 25.01.29.29c1a0aa07 /Account/Login ReturnUrl Yago Martins redirect
A vulnerability labeled as problematic has been found in Zenvia Movidesk up to 25.01.29.29c1a0aa07. Affected by this vulnerability is an unknown functionality of the file /Account/Login. The manipulation of the argument ReturnUrl with the input //evil.com as part of string results in open redirect.
This vulnerability is known as CVE-2025-0970. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The affected component should be upgraded.