Impact
Adobe Commerce, including B2B, Webhooks Plugin, and Magento Open Source, has an Improper Redirect (Open Redirect) flaw that allows an attacker to craft a malicious URL. When a user follows the link, they are redirected to an attacker‑controlled site, which can be used for phishing and credential theft. The weakness falls under CWE‑601 and represents an open redirect that bypasses security controls.
Affected Systems
The affected products are Adobe Commerce, Adobe Commerce B2B, Adobe Commerce Webhooks Plugin, and Magento Open Source. No specific version information is listed, so administrators must verify whether their current installations expose this vulnerability and apply remediation accordingly.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating low to moderate severity, and an EPSS score of less than 1%, signifying a low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires user interaction—typically clicking a crafted link—making it a social engineering vector rather than an automated attack. Attackers can leverage the redirect to conduct phishing, credential theft, or account takeover, but the system itself remains otherwise unaffected.
OpenCVE Enrichment