← Back to browse · API

CVE-2024-52875

Severity
HIGH
CVSS
8.8
EPSS
0.29558
Risk score
45.55
CISA KEV
No
PoC
No
Published
2025-01-31
Modified
2025-02-12
First seen
2026-08-07
Aliases
EUVD-2024-46263, GHSA-WWWQ-JMFM-4F5C
Products
GFI Software:Kerio Control 9.2.5 ≤9.4.5
Sources
euvd EUVD-2024-46263

Description

An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.

References