CVE-2024-49706

Publication date

2025-04-14 12:05:50

Family

CERT-PL

State

PUBLISHED

Description

Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0