Executive brief
OpenMage Magento LTS is an e-commerce platform used to manage online stores. A vulnerability in the product stock notification system allows attackers to redirect logged-in customers to malicious external websites. This can be used to facilitate phishing attacks, steal login credentials, or distribute malware by leveraging the trust customers have in the store's legitimate domain.
Technical details
An open redirect vulnerability exists in Mage_ProductAlert_AddController::stockAction() due to insufficient validation of the 'uenc' parameter. When a request is made with a non-existent 'product_id', the controller fails to call _isUrlInternal() before passing the 'uenc' value to _redirectUrl(). An attacker can craft a malicious URL that, when clicked by a logged-in customer, triggers a 302 redirect to an arbitrary destination. This vulnerability is particularly effective for phishing or stealing OAuth tokens if social login is implemented. The issue is patched in version 20.18.0.
Affected products
- OpenMage magento-lts <= 20.17.0
Timeline
- 2026-05-04: disclosed
- 2026-05-05: advisory: GitHub Advisory published
- 2026-05-15: other: NVD publication