NA

CVE-2024-24525

Published: 29/02/2024 Updated: 29/02/2024

Vulnerability Summary

An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote malicious user to execute arbitrary code via the infoid parameter of the URL.

Github Repositories

EpointWebBuilder_v5x_VULN [CVE ID] CVE-2024-24525 [VulnerabilityType Other] Open redirect vulnerability [Affected Product Code Base] EpointWebBuilder - V5x [CVE Impact Other] allows a remote unauthenticated attacker to redirect users to arbitrary websites and conduct phishing attacks via a specially crafted URL Step Tests revealed the following links in the site: htt