CVE-2025-30859

CVSS 3.1 Score 4.7 of 10 (medium)

Details

Published Mar 27, 2025
CWE ID 601

Summary

CVE-2025-30859 is a new Open Redirect vulnerability affecting AliNext, a popular e-commerce plugin for Magento. Hackers can exploit this issue by manipulating URLs, redirecting unsuspecting users to fraudulent or malicious websites. This allows attackers to carry out phishing attacks and gain unauthorized access to sensitive user information. AliNext versions from n/a through 3.5.1 are impacted by this vulnerability. It is crucial that users of these affected versions take immediate action to apply the latest patches or upgrades to secure their websites against these attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share