Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79.0
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://cert.pl/en/posts/2025/04/CVE-2024-10087 | third party advisory |
https://www.iksoris.pl/system-rezerwacji-i-sprzedazy-biletow-iksoris.html | product |