Metrics
Affected Vendors & Products
Tue, 11 Mar 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-601 |
Tue, 11 Mar 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Mar 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component Login Page. The manipulation of the argument inpRedirectURL leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component Login Page. The manipulation of the argument inpRedirectURL leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. |
Title | Stoque Zeev.it Login Page redirect | Stoque Zeev.it Login Page server-side request forgery |
Weaknesses | CWE-918 | |
Metrics |
cvssV2_0
|
cvssV2_0
|
Tue, 11 Mar 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability, which was classified as problematic, was found in Stoque Zeev.it 4.24. This affects an unknown part of the file /Login?inpLostSession=1 of the component Login Page. The manipulation of the argument inpRedirectURL leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | Stoque Zeev.it Login Page redirect | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-03-11T13:00:08.465Z
Updated: 2025-03-11T13:50:51.697Z
Reserved: 2025-03-11T06:56:33.686Z
Link: CVE-2025-2192

Updated: 2025-03-11T13:50:46.608Z

Status : Received
Published: 2025-03-11T13:15:43.780
Modified: 2025-03-11T14:15:27.443
Link: CVE-2025-2192

No data.