Executive brief
The Restajet Online Food Delivery System contains a security flaw that allows attackers to redirect users to malicious websites. This type of vulnerability is commonly used in phishing campaigns to trick customers or staff into providing login credentials or downloading malware by making a malicious link appear to come from a trusted domain. Because the vendor has not responded to disclosure attempts, a fix may not be available.
Technical details
An open redirect vulnerability (CWE-601) exists in the Restajet Online Food Delivery System through version 19122025. The application fails to properly validate user-supplied input used in redirection targets, allowing a remote attacker with low privileges to craft a URL that redirects victims to an arbitrary external domain. Exploitation requires user interaction, typically via a phishing link. Successful exploitation can facilitate credential harvesting or the delivery of malicious payloads under the guise of the trusted application's domain. As of the advisory date, the vendor has not responded to reports, and no patch has been confirmed.
Affected products
- Restajet Information Technologies Inc. Online Food Delivery System through 19122025
Timeline
- 2025-12-19: disclosed: Initial disclosure by TR-CERT (USOM)
- 2025-12-19: advisory: NVD publication date