Executive brief
Universal Software Inc. FlexCity, a smart city management platform, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can send them to a fraudulent site that looks legitimate to steal login credentials or deliver malware. This type of attack exploits the trust users have in the official FlexCity domain to facilitate phishing campaigns.
Technical details
An open redirect vulnerability (CWE-601) exists in Universal Software Inc. FlexCity versions 5.536.0 through 11052026. The application fails to properly validate user-supplied input used in redirection targets, allowing a remote, unauthenticated attacker to craft a URL that redirects victims to an arbitrary external domain. Exploitation requires minimal user interaction, typically via a phishing link. This can be used to facilitate credential theft or bypass security filters that trust the affected domain. The vulnerability was reported by the Computer Emergency Response Team of the Republic of Turkey.
Affected products
- Universal Software Inc. FlexCity 5.536.0 through 11052026
Timeline
- 2026-07-21: advisory: NVD published the CVE record based on TR-CERT data.
- 2026-07-21: disclosed