PT-2025-10776 · Zucchetti · Zucchetti Ad Hoc Infinity

Published

2025-03-11

·

Updated

2025-03-11

·

CVE-2024-51321

CVSS v3.1

7.6

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zucchetti Ad Hoc Infinity version 2.4
Description: The issue is related to an improper check on the m cURL parameter, which allows an attacker to redirect the victim to an attacker-controlled website after authentication.
Recommendations: For Zucchetti Ad Hoc Infinity version 2.4, consider restricting access to the m cURL parameter to prevent unauthorized redirects until a patch is available.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-51321

Affected Products

Zucchetti Ad Hoc Infinity