Description
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not be accepted as the server returns an error message. Since this parameter is sent as part of a session cookie, the issue persists until the session expires or the user deletes cookies manually. Similar effect might be achieved when a user tries to change platform language to an unimplemented one. This vulnerability has been patched in version 79.0
INFO
Published Date :
2025-04-14T12:05:35.366Z
Last Modified :
2025-04-14T12:54:05.732Z
Source :
CERT-PL
AFFECTED PRODUCTS
The following products are affected by CVE-2024-49705 vulnerability.
| Vendors | Products |
|---|---|
| Softcom.wroc |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2024-49705.