Impact
The vulnerability remains an open redirect flaw in the FlexCity application. A crafted URL can force the application to redirect users to arbitrary, untrusted sites, as identified in the updated description. The flaw arises from insufficient validation of redirect parameters, enabling input data manipulation. This weakness corresponds to CWE-601 (Open Redirect).
Affected Systems
Universal Software Inc.'s FlexCity product, versions 5.536.0 to 5.542.0, exclusive.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate level of severity, with the likelihood of exploitation shown as negligible by the EPSS of less than 1%. The vulnerability is not currently listed in CISA’s KEV catalog. Attackers would typically need to lure a victim to click a crafted link or submit a specially crafted request, implying a user‑interaction requirement. The impact is limited to the context of the redirected user.
OpenCVE Enrichment