Impact
The GoodBarber plugin contains an open redirection flaw (CWE-601) that allows an attacker to craft URLs which, when clicked by a visitor, redirect the user to an arbitrary untrusted site. This can be used to facilitate phishing, drive users to malicious landing pages, or prime them for further attacks, though it does not grant code execution or direct system compromise. The impact is therefore limited to user deception and loss of trust rather than direct integrity or availability damage.
Affected Systems
The flaw exists in GoodBarber GoodBarber plugin versions from the earliest release through version 1.0.26. Any installation of the plugin in these versions is vulnerable. No other vendors or product lines are listed as affected.
Risk and Exploitability
The CVSS score of 4.7 rates the vulnerability as medium severity; however the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The vulnerability is not present in the CISA KEV catalog. The attack vector is likely user‑directed; an attacker must supply or embed the malicious URL in a context that a user may click, such as emails or third‑party sites.
OpenCVE Enrichment
EUVD