CVE ID | CVE-2023-6552 |
Publication date | 08 January 2024 |
Vendor | TasmoAdmin |
Product | TasmoAdmin |
Vulnerable versions | All below 3.3.0 |
Vulnerability type (CWE) | URL Redirection to Untrusted Site (CWE-601) |
Report source | Own research |
Description
During its own research, CERT Polska has found a vulnerability in TasmoAdmin software. Lack of "current" GET parameter validation when changing a language leads to an open redirect vulnerability.
The vulnerability has been assigned the ID CVE-2023-6552 and was fixed in version 3.3.0.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.