Description
URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation.

This issue affects FlexCity: from 5.536.0 before 5.542.0.
Published: 2026-07-21
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability remains an open redirect flaw in the FlexCity application. A crafted URL can force the application to redirect users to arbitrary, untrusted sites, as identified in the updated description. The flaw arises from insufficient validation of redirect parameters, enabling input data manipulation. This weakness corresponds to CWE-601 (Open Redirect).

Affected Systems

Universal Software Inc.'s FlexCity product, versions 5.536.0 to 5.542.0, exclusive.

Risk and Exploitability

The CVSS score of 6.1 indicates a moderate level of severity, with the likelihood of exploitation shown as negligible by the EPSS of less than 1%. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers would typically need to lure a victim to click a crafted link or submit a specially crafted request, implying a user‑interaction requirement. The impact is limited to the context of the redirected user.

Generated by OpenCVE AI on August 4, 2026 at 05:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FlexCity to a version released after 5.542.0 that contains the fix for the open redirect issue.
  • Implement a whitelist of allowed redirect destinations, rejecting any URLs that are not signed or validated against an internal domain list.
  • Monitor outbound redirect logs for anomalous URL patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026. URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 before 5.542.0.

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Universal Software Inc.
Universal Software Inc. flexcity
Vendors & Products Universal Software Inc.
Universal Software Inc. flexcity

Tue, 21 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.536.0 through 11052026.
Title Open Redirect in Universal Sotware's FlexCity
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Universal Software Inc. Flexcity
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-28T11:31:51.228Z

Reserved: 2026-05-11T06:58:41.546Z

Link: CVE-2026-8284

cve-icon Vulnrichment

Updated: 2026-07-21T16:15:23.423Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')