Unknown · Stoque Zeev.It · CVE-2025-2192
Name of the Vulnerable Software and Affected Versions:
Stoque Zeev.it version 4.24
Description:
A problematic issue was found in the Login Page component, specifically affecting the "/Login?inpLostSession=1" endpoint. The manipulation of the `inpRedirectURL` argument leads to server-side request forgery, which can be initiated remotely. The issue has been publicly disclosed.
Recommendations:
For version 4.24, as a temporary workaround, consider restricting access to the "/Login?inpLostSession=1" endpoint to minimize the risk of exploitation. Avoid using the `inpRedirectURL` argument in the affected Login Page component until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.