Impact
An open‑redirect flaw exists in the OAuth/OIDC authentication flow of the Axivion Dashboard. The login process does not verify that the post‑authentication redirect URL remains within the application's origin, allowing an attacker to craft a link that steers an authenticated user to an arbitrary external site. This flaw can be abused for phishing, enabling attackers to provide a convincing look‑alike page and harvest credentials or second‑factor tokens. The weakness is identified as CWE‑601.
Affected Systems
The vulnerability affects the Axivion Dashboard, part of the Qt Axivion product line. All releases before Axivion 7.9.13, 7.10.11, 7.11.7, and 7.12.2 are impacted. Versions 7.9.13 and newer, 7.10.11 and newer, 7.11.7 and newer, and 7.12.2 and newer contain the fix and are not affected.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate to high risk, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation at this time. Exploitation requires a socially engineered scenario where a victim follows a maliciously crafted login link and completes the authentication flow, after which the attacker can redirect the user to a look‑alike phishing site.
OpenCVE Enrichment