5.1
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.
Basic Information
ID
CVE-2025-41083
Source
INCIBE
Published
Jan 26, 2026 at 09:42
Modified
Jan 26, 2026 at 09:43
Affected Product
Vendor
Altitude
Product
Altitude Communication Server
Version
8.5.3290.0
Affected Versions
Altitude Altitude Communication Server 8.5.3290.0