Impact
The server does not validate avatar image URLs, allowing attackers to embed arbitrary external content in profile pictures. This flaw enables users to be directed to malicious third‑party servers, exposing them to tracking or hidden scripts. The vulnerability is a classic example of Unrestricted Upload of Dangerous File Type (CWE‑434).
Affected Systems
The affected product is Apache Answer from the Apache Software Foundation, versions up to and including 2.0.0.
Risk and Exploitability
The CVSS score is 6.5 and the EPSS score is less than 1%; the vulnerability is not listed in CISA’s KEV catalog. Any user who can set a profile image can exploit this issue with minimal effort, as the server processes the supplied URL without sufficient validation. Although it does not grant direct code execution, the ability to force user browsers to contact arbitrary third‑party servers poses a significant privacy and tracking risk.
OpenCVE Enrichment