Report an incident
Report an incident

Vulnerability in TasmoAdmin software
08 January 2024 | CERT Polska | #vulnerability, #warning, #cve
CVE ID CVE-2023-6552
Publication date 08 January 2024
Vendor TasmoAdmin
Product TasmoAdmin
Vulnerable versions All below 3.3.0
Vulnerability type (CWE) URL Redirection to Untrusted Site (CWE-601)
Report source Own research

Description

During its own research, CERT Polska has found a vulnerability in TasmoAdmin software. Lack of "current" GET parameter validation when changing a language leads to an open redirect vulnerability.

The vulnerability has been assigned the ID CVE-2023-6552 and was fixed in version 3.3.0.


More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.