Impact
A URL redirection flaw in Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources allows attackers to send users to arbitrary, untrusted sites. This open redirect can be leveraged to craft phishing pages that appear legitimate to staff, resulting in credential theft or malware delivery. The weakness falls under CWE-601: Unvalidated Redirect or Forward.
Affected Systems
The issue impacts Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources, specifically version 26.0 and earlier. Upgrading to version 26.1 or later addresses the vulnerability.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, implying that major exploits have not been publicly confirmed. Likely attack vectors involve a web-based user clicking a crafted link or receiving a malicious email that utilizes the open redirect feature. If exploited, the attacker could redirect legitimate users to phishing sites that mimic internal or external domains.
OpenCVE Enrichment