Impact
The vulnerability allows an unauthenticated attacker to influence the redirectUrl POST parameter in the login flow. By tampering with this value the attacker can cause authenticated users to be automatically redirected to an arbitrary external site after login. This can be used to harvest credentials or deliver phishing content. The weakness is a classic open redirect (CWE-601).
Affected Systems
Leantime version 3.6.2 and earlier are affected. The redirectUrl parameter is processed by the Login controller in this release of the web application.
Risk and Exploitability
The EPSS value is 0.00197 (<1%), indicating a very low exploitation probability. The CVSS score of 5.1 indicates a moderate risk. Because the flaw is an open redirect, exploitation does not require privileged access or a local vulnerability; it can be triggered simply by supplying a crafted login URL. The vulnerability can be trivially exercised by any attacker in control of a link. The issue is not yet listed in the CISA KEV catalog, so no known widespread exploitation is reported at this time.
OpenCVE Enrichment