URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.
The attacker prepares a specially crafted link to DivvyDrive containing a manipulated URL parameter pointing to an externally controlled website. When the victim clicks on such a link (requiring user interaction — UI:R), the application processes the parameter without proper validation and redirects the user to a malicious site. The parameter injection mechanism enables bypass of potential filters and embedding of unauthorized target value in the redirect.
An attacker can trick a user into visiting a malicious website, which may consequently lead to phishing, credential theft, malware installation, or session hijacking. High CVSS score indicates potential serious breach of confidentiality, integrity, and availability of user resources.
DivvyDrive should be updated to version 4.8.3.2 or newer. Detailed information is available in the manufacturer's references and security notification at: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0182
DivvyDrive in versions from 4.8.2.9 to 4.8.3.2 (exclusively), meaning versions from 4.8.2.9 inclusive before version 4.8.3.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H