CVE-2025-11240
Last modified
CVE-2025-11240 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
An open redirect vulnerability existed in KNIME Business Hub prior to version 1.16.0. An unauthenticated remote attacker could craft a link to a legitimate KNIME Business Hub installation which, when opened by the user, redirects the user to a page of the attackers choice. This might open the possibility for fishing or other similar attacks. The problem has been fixed in KNIME Business Hub 1.16.0.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Knime | Business Hub | < 1.16.0 |
References
- https://www.knime.com/security/advisoriesVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-11240?
How severe is CVE-2025-11240?
How do I fix CVE-2025-11240?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-11233Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3…6.3
- CVE-2025-11234A flaw was found in QEMU. If the QIOChannelWebsock object is…7.5
- CVE-2025-11235Unverified Password Change vulnerability in Progress MOVEit …7.5
- CVE-2025-11237The Make Email Customizer for WooCommerce WordPress plugin t…5.3
- CVE-2025-11238The Watu Quiz plugin for WordPress is vulnerable to Stored C…7.2
- CVE-2025-11239Potentially sensitive information in jobs on KNIME Business …4.3
- CVE-2025-11241The Yoast SEO Premium plugin for WordPress is vulnerable to …6.4
- CVE-2025-11242Server-Side Request Forgery (SSRF) vulnerability in Teknolis…9.8
- CVE-2025-11243Allocation of Resources Without Limits or Throttling vulnera…8.3
- CVE-2025-11244The Password Protected plugin for WordPress is vulnerable to…3.7
- CVE-2025-11246GitLab has remediated an issue in GitLab CE/EE affecting all…5.4
- CVE-2025-11247GitLab has remediated an issue in GitLab EE affecting all ve…4.3
Are you affected by CVE-2025-11240?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
