Impact
CWE-601 describes an open redirect flaw that permits an attacker to redirect a victim to an arbitrary untrusted site, enabling phishing, credential theft, or delivery of malicious content without the user’s knowledge. In this case the Access Control System allows redirect URLs to be set without proper validation, so any attacker who can craft a URL to the system can force a legitimate user to a malicious domain.
Affected Systems
Armiya Information Technologies Ltd. Co. offers an Access Control System. Versions prior to Versiyon 2 are affected. No other affected versions or products are listed.
Risk and Exploitability
The CVSS score of 9.3 indicates the flaw is high severity and potentially catastrophic. While the EPSS score is not available, the lack of a KEV listing does not reduce the risk because the vulnerability remains exploitable. The attack likely occurs through a crafted link or form parameter that specifies a redirect destination. Without input validation, an attacker can mount phishing attacks against users of the system.
OpenCVE Enrichment