Executive brief
Milk admin, an open-source PHP administration panel and dashboard, contains a security flaw that allows attackers to redirect users to malicious websites. By sending a specially crafted link to a user, an attacker can trick them into visiting a fraudulent site that may look like a legitimate login page or contain malware. This type of attack is often used in phishing campaigns to steal user credentials or damage an organization's reputation.
Technical details
An open redirect vulnerability exists in Milk admin <=0.9.8 due to insufficient validation of the 'redirect' parameter within the application's routing logic. Specifically, the components 'App/Route.php' and 'public_html/index.php' fail to restrict redirection targets to trusted domains. A remote, unauthenticated attacker can exploit this by crafting a URL that includes a malicious external destination in the redirect parameter. When a victim clicks the link, the application automatically forwards them to the attacker-controlled site. As of the advisory date, no official patch has been released, and administrators are advised to manually restrict or monitor the affected parameter.
Affected products
- giuliopanda Milk admin <=0.9.8
Timeline
- 2026-07-27: disclosed
- 2026-07-27: advisory: NVD publication date
References
- https://github.com/1337Skid/CVE-2026-51564
- https://github.com/giuliopanda/milk-admin/
- https://github.com/giuliopanda/milk-admin/blob/6389386de2a9226c84ecb7e79cd16d7c027952ad/milkadmin/App/Route.php
- https://github.com/giuliopanda/milk-admin/blob/6389386de2a9226c84ecb7e79cd16d7c027952ad/public_html/index.php