CyberRota Analysis
AI-GeneratedThe vulnerability exists in the password reset functionality, where the application improperly handles the 'url' parameter, allowing an attacker to redirect users to arbitrary external sites post-password reset. This could lead to phishing attacks or other malicious activities targeting users. Organizations utilizing this feature should prioritize remediation to protect their users from potential exploitation.
Original NVD Description
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.