Impact
A crafted base64‑encoded redirect parameter is accepted by the Helix Ultimate extension without any validation to confirm that the resolved URL is internal. The flaw allows an attacker to redirect users to arbitrary external sites, potentially leading to phishing or other malicious payloads. This vulnerability is categorized under CWE‑601 and can be abused without authentication when a user follows a malicious link.
Affected Systems
The issue affects joomshaper.com's Helix Ultimate Joomla extension for versions earlier than 2.2.10. Any Joomla installation that uses this extension and remains on a vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. With the EPSS score unavailable and the vulnerability not listed in CISA KEV, the likelihood of immediate exploitation is unclear, but the open redirect can be used for social engineering or to bypass same‑origin policies. An attacker could embed a malicious link that constructs a base64 string resolving to an external domain and share it with users or embed it in other content. Successful exploitation would divert users to attacker‑controlled sites, enabling credential theft, malware downloads, or further web‑based attacks.
OpenCVE Enrichment