Description
URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing.

This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Published: 2026-08-04
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A URL redirection flaw in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources allows attackers to send users to arbitrary, untrusted sites. This open redirect can be leveraged to craft phishing pages that appear legitimate to staff, resulting in credential theft or malware delivery. The weakness falls under CWE-601: Unvalidated Redirect or Forward.

Affected Systems

The issue impacts Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources, specifically version 26.0 and earlier. Upgrading to version 26.1 or later addresses the vulnerability.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk level. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying that major exploits have not been publicly confirmed. Likely attack vectors involve a web-based user clicking a crafted link or receiving a malicious email that utilizes the open redirect feature. If exploited, the attacker could redirect legitimate users to phishing sites that mimic internal or external domains.

Generated by OpenCVE AI on August 4, 2026 at 20:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade HUMANIST Digital Human Resources to version 26.1 or later to eliminate the open redirect flaw.
  • Configure the application to allow redirects only to a predefined whitelist of trusted domains, reducing unintended navigation.
  • Apply web application firewall rules that detect and block anomalous redirect patterns, providing an additional layer of protection.

Generated by OpenCVE AI on August 4, 2026 at 20:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources
Vendors & Products Bilin Software And Informatics Consultancy Inc.
Bilin Software And Informatics Consultancy Inc. humanist Digital Human Resources

Tue, 04 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Phishing. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.
Title URL Redirection in Bilin Software's HUMANIST Digital Human Resources
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Bilin Software And Informatics Consultancy Inc. Humanist Digital Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T13:12:55.745Z

Reserved: 2026-06-30T11:40:05.262Z

Link: CVE-2026-14219

cve-icon Vulnrichment

Updated: 2026-08-04T13:12:37.712Z

cve-icon NVD

Status : Received

Published: 2026-08-04T10:19:32.173

Modified: 2026-08-04T14:16:30.360

Link: CVE-2026-14219

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:21:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')