Impact
The setReferrer function in the Trusted Backend component contains a flaw that allows an attacker to supply a crafted href argument, causing the application to perform an open redirect to an arbitrary destination. This vulnerability is classified as CWE-601. An attacker could use the redirect to lure users to malicious sites, potentially facilitating phishing or malicious payload delivery. The bug can be triggered remotely, and the CVE description does not specify any authentication requirement, leaving it unclear whether authentication is needed to exploit the issue.
Affected Systems
Versions of the kirilkirkov Ecommerce-CodeIgniter-Bootstrap repository that include the Trusted Backend component up to commit 95dfa8cebbb87ab46ae450643a follows a rolling release schedule, no formal version numbers are published; administrators should compare the commit hash of their deployment against the known affected commit to determine if remediation is required.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, mainly due to the remote nature and the potential for deceptive redirects. An EPSS score below 1% suggests a low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. with a crafted link, directing victims to attacker‑controlled destinations and bypassing security controls. The specific authentication or privilege conditions required for exploitation are not described in the CVE data.
OpenCVE Enrichment