Impact
A low‑privileged authenticated API user can provide attacker‑controlled forwardToUrl and redirectUrl values when initiating password reset or account confirmation flows in dataCycle‑CORE up to version 25.07.3. The system inserts these URLs into outgoing emails and later redirects the user’s browser, without host allowlisting. This classic open redirect flaw (CWE‑601) enables an attacker to send a victim a reset or confirmation link that contains a valid token and makes the victim follow a link to a malicious domain. The result is token interception, account hijacking, or phishing. The vulnerability directly compromises the confidentiality of reset tokens and the integrity of the account recovery process.
Affected Systems
The affected product is datacycle‑engine's dataCycle‑CORE, in all versions up to and including 25.07.3. The issue was fixed in version 26.06.08 and newer.
Risk and Exploitability
The CVSS score of 7.3 marks the vulnerability as high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation today, yet the flaw is not listed in the CISA KEV catalog. Exploitation requires only low‑privileged API access; an attacker can trigger a password reset or confirmation, supply malicious URLs, and then capture the token when the victim opens the email or is redirected after completion.
OpenCVE Enrichment