CVE Database
/

CVE-2025-41083

Back to search

CVE-2025-41083

Published: Jan 26, 2026

Modified: Jan 26, 2026

PUBLISHED

Description

Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior can be used to redirect clients to endpoints controlled by the attacker.

VendorProductVersions

Altitude

Altitude Communication Server

affected
8.5.3290.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now