Impact
This vulnerability allows an attacker to cause a web user to be redirected to an arbitrary malicious site by manipulating URLs in Adobe Commerce. The weakness is a classic open redirect flaw (CWE‑601) and requires the victim to interact with a crafted link. If exploited, an attacker could deceive customers into visiting phishing sites or downloading malware, compromising confidentiality and potentially delivering credential theft or further compromise.
Affected Systems
Affected Adobe Commerce versions are 2.4.9‑alpha3, 2.4.8‑p3, 2.4.7‑p8, 2.4.6‑p13, 2.4.5‑p15, 2.4.4‑p16 and all earlier releases. These include the corresponding Magento Open Source releases referenced in the CPE list.
Risk and Exploitability
The CVSS v3.1 base score is 3.1, indicating low to moderate severity. The EPSS score is below 1%, meaning the probability of widespread exploitation is low, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a crafted URL to be presented to a user who must click or otherwise engage with it; thus the attack vector is web‑based with user interaction.
OpenCVE Enrichment