CVE-2024-52875

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 31, 2025
CWE ID 113

Summary

CVE-2024-52875 is a vulnerability affecting GFI Kerio Control versions 9.2.5 to 9.4.5. The issue lies in the lack of proper sanitization of the dest GET parameter in the /nonauth/addCertException.cs, /nonauth/guestConfirm.cs, and /nonauth/expiration.cs pages. This can be exploited through Open Redirect or HTTP Response Splitting attacks, enabling Reflected Cross-Site Scripting (XSS). Moreover, remote command execution can be achieved by taking advantage of the upgrade feature in the admin interface.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share