Impact
The updated description now indicates an open-redirect flaw in the Hikashop extension for Joomla. The exact details of the flaw are not provided in the new data, but it continues to be a CWE‑601 type vulnerability that can allow attackers to redirect users to arbitrary external sites, potentially enabling phishing or malicious content delivery.
Affected Systems
The flaw affects all installations of the Hikashop extension for Joomla with a version number less than 6.5.2. No specific sub‑version details are documented, so any version that predates 6.5.2 is potentially vulnerable.
Risk and Exploitability
The attacker can exploit the vulnerability by crafting a URL that includes a redirect parameter pointing to a malicious destination. The CVSS score of 6.1 reflects moderate severity, while the EPSS score of <1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, so it is not known to be actively exploited. The primary risk is the facilitation of phishing attacks that could lead to credential theft or malicious site visits, rather than direct compromise of the system.
OpenCVE Enrichment