CVE-2025-5256 | Mautic up to 6.0.1/5.2.5/4.4.15 0 endpoint returnUrl redirect (GHSA-6vx9-9r2g-8373)
A vulnerability was found in Mautic up to 6.0.1/5.2.5/4.4.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /s/action/unlock/user.user/0 endpoint. The manipulation of the argument returnUrl leads to open redirect.
This vulnerability is handled as CVE-2025-5256. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.