Impact
The vulnerability allows an attacker to manipulate the end‑of‑path mapping of UrlFileNameViewController in Spring MVC applications that do not have a configured prefix. When an attacker supplies a crafted URL, the application can redirect the user to a malicious site without validation, enabling phishing, credential theft, or other social‑engineering attacks. The flaw does not grant direct code execution or data disclosure, but it can be used to undermine user trust and facilitate secondary attacks.
Affected Systems
Spring Framework versions 7.0.0 through 7.0.8, 6.2.0 through 6.2.19, 6.1.0 through 6.1.28, 6.0.0 through 6.0.30, 5.3.0 through 5.3.49, and 5.2.25.RELEASE and earlier are affected. The issue exists in applications that map UrlFileNameViewController to an end‑of‑path and omit a prefix in the configuration.
Risk and Exploitability
The CVSS score is not publicly disclosed in the provided data, but the presence of an unrestricted redirect indicates a high potential impact. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, yet the flaw is well‑known in the community and can be triggered via a simple crafted URL. It is inferred that the attack vector is a web request containing a malicious redirect target. Since the vulnerability is not mitigated by internal network controls, it remains exploitable in any network context where the application is reachable.
OpenCVE Enrichment