Executive brief
Logo Cloud, a business management and cloud services platform, is affected by a security flaw that allows attackers to redirect users to malicious websites. By tricking a logged-in user into clicking a specially crafted link, an attacker can facilitate phishing attacks or bypass certain navigation restrictions. This could lead to the theft of user credentials or the delivery of malware by making a malicious site appear as a legitimate part of the Logo Cloud service.
Technical details
An open redirect vulnerability (CWE-601) exists in Logo Software Inc. Logo Cloud versions prior to 2025.R6. The application fails to properly validate user-supplied input used in URL redirection, allowing a remote attacker with low privileges to craft a malicious URL. If a victim clicks this link while authenticated, they are redirected to an arbitrary external domain. This vulnerability can be leveraged for phishing campaigns or to bypass security controls that rely on trusted referrers. The issue is resolved in version 2025.R6.
Affected products
- Logo Software Inc. Logo Cloud before 2025.R6
Timeline
- 2025-10-06: disclosed
- 2025-10-06: advisory