5.3
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in LaChatterie Verger up to 1.2.10. This impacts the function redirectToAuthorization of the file /src/main/services/mcp/oauth/provider.ts. The manipulation of the argument URL results in deserialization. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2025-11273
Source
VulDB
Published
Oct 4, 2025 at 23:02
Affected Product
Vendor
LaChatterie
Product
Verger
Version
1.2.0
Affected Versions
LaChatterie Verger 1.2.0
LaChatterie Verger 1.2.1
LaChatterie Verger 1.2.2
LaChatterie Verger 1.2.3
LaChatterie Verger 1.2.4
LaChatterie Verger 1.2.5
LaChatterie Verger 1.2.6
LaChatterie Verger 1.2.7
LaChatterie Verger 1.2.8
LaChatterie Verger 1.2.9
LaChatterie Verger 1.2.10
LaChatterie Verger 1.2.1
LaChatterie Verger 1.2.2
LaChatterie Verger 1.2.3
LaChatterie Verger 1.2.4
LaChatterie Verger 1.2.5
LaChatterie Verger 1.2.6
LaChatterie Verger 1.2.7
LaChatterie Verger 1.2.8
LaChatterie Verger 1.2.9
LaChatterie Verger 1.2.10