---
id: CVE-2025-34504
title: >-
  KodExplorer 4.52 contains an open redirect vulnerability in the user login
  page that allows attackers to manipulate the 'link' parameter
summary: >-
  KodExplorer 4.52 contains an open redirect vulnerability in the user login
  page that allows attackers to manipulate the 'link' parameter. Attackers can
  craft malicious URLs in the link parameter to redirect users to arbitrary
  external we…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-601
vendor: kodcloud
product: kodexplorer
affected:
  - kodexplorer = 4.52
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-34504'
references:
  - url: 'https://github.com/kalcaddle/KodExplorer/releases/tag/4.52'
    label: disclosure@vulncheck.com
  - url: 'https://kodcloud.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/52245'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/kodexplorer-open-redirect-vulnerability-via-user-login-endpoint
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00321
epssPercentile: 0.22943
ingestedAt: '2026-10-07T20:46:46.867Z'
---

## Overview

KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the 'link' parameter. Attackers can craft malicious URLs in the link parameter to redirect users to arbitrary external websites after authentication.

## Affected

- `kodexplorer = 4.52`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
