Impact
The Meeting Room Booking System is vulnerable to an unauthenticated open redirect that allows an attacker to supply a query‑specified URL to which a user will be redirected without authentication. This flaw, classified as CWE‑601, can be used to send users to phishing sites or spoofed login pages, thereby facilitating credential theft or other social‑engineering attacks.
Affected Systems
Any installation of the Meeting Room Booking System (MRBS) utilizing the mrbs-code product from the meeting‑room‑booking‑system vendor and running a version older than 1.12.2 is affected. Version 1.12.2 and later contain the necessary fix.
Risk and Exploitability
The CVSS score of 6.9 reflects moderate severity, with no exploit probability data available and the vulnerability not listed in the CISA KEV catalog. Attackers can exploit the flaw simply by injecting a crafted redirection URL into a published link, requiring no authentication or privileged access. The likelihood of an attack increases in environments where users click external links or share URLs with colleagues.
OpenCVE Enrichment