Impact
An open redirect vulnerability exists in the redirect parameter of Milk admin version 0.9.8 and earlier, allowing a remote attacker to craft a request that forces user browsers to navigate to any external site. This flaw can be leveraged to deliver phishing pages or malicious content, compromising user trust and potentially leading to credential theft or further attacks. The weakness is rooted in improper validation of redirect targets, classified under CWE‑601.
Affected Systems
Milk admin, versions 0.9.8 and below are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The vulnerability is remotely exploitable via a crafted HTTP request that includes a redirect parameter pointing to an external URL. The CVSS score is 4.9, indicating low-to-medium severity, while the EPSS score is <1%, reflecting a very low exploitation probability. The vulnerability is not listed in CISA KEV. The attack requires the victim to visit the vulnerable application, making it a classic open‑redirect that can be widely triggered through malicious link insertion or email redirects. Prioritizing remediation is advisable given the risk of user confusion and phishing.
OpenCVE Enrichment