What the vulnerability does
01Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in AAM Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More.This issue affects Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More: from n/a through 6.9.18.
Explanation of Vulnerability in Simple Terms
02Summary
Advanced Access Manager contains an open redirect vulnerability that allows an attacker to redirect users to an external website by crafting a malicious link. The vulnerability requires user interaction—the victim must click the link. The redirect can leak the user's session information to the external site. Update to a version newer than 6.9.18.
What an attacker can do
03Attacker Capabilities
Redirect site users to a malicious external website, potentially stealing their session tokens or credentials.
Potential impact on your site
04Site Impact
Users may be phished or have credentials stolen if redirected to a fake login page mimicking your site.
Conditions required to exploit
05Prerequisites
No authentication required. The victim must click a crafted link containing a malicious redirect parameter.
Key dates
06Disclosure timeline
December 29, 2023
CVE published
April 28, 2026
Record updated