Impact
The vulnerability is a URL redirection flaw that allows an attacker to direct users to arbitrary, potentially malicious sites. This open redirect can be exploited by any unauthenticated user who supplies a crafted URL. The weakness, identified as CWE-601, undermines trust and may facilitate phishing or malware delivery, affecting confidentiality and user safety but not system integrity directly.
Affected Systems
The flaw affects Abis Technology Ltd. Co.'s AVESİS software. Versions prior to 2026-08-24 03:51, specifically those dated 2026-08-20 13:31 or earlier, are vulnerable.
Risk and Exploitability
With a CVSS score of 5.4, the threat is medium severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely network‑based via browsers, requiring no authentication. While exploitation does not grant direct system compromise, users can be misdirected to harmful sites, increasing the risk of credential theft and malware infections.
OpenCVE Enrichment