Impact
Adobe Commerce is affected by an Improper Redirect (Open Redirect) vulnerability that could result in a Security feature bypass. An attacker could construct a malicious URL that redirects a victim to an attacker-controlled site. Exploitation of this issue requires user interaction in that a victim must click on a malicious link. The flaw allows the attacker to redirect users to external domains, facilitating phishing and credential theft, as described by CWE-601. Scope is changed, indicating that the vulnerability might affect the system’s overall security posture.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. No specific version information is listed, so administrators must verify whether their current installations expose this vulnerability and apply remediation accordingly.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.1, indicating medium to high severity, and an EPSS score of less than 1%, signifying a low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires user interaction—typically clicking a crafted link—making it a social engineering vector rather than an automated attack. Attackers can leverage the redirect to conduct phishing, credential theft, or account takeover, but the system itself remains otherwise unaffected.
OpenCVE Enrichment