CVE-2024-28344

LOW

Sipwise C5 NGCP Dashboard < mr11.5.1 - Open Redirect via Double-Encoded URL Parameter

Title source: llm
STIX 2.1

Description

An Open Redirect vulnerability was found in Sipwise C5 NGCP Dashboard below mr11.5.1. The Open Redirect vulnerability allows attackers to control the "back" parameter in the URL through a double encoded URL.

References (1)

Core 1

Scores

CVSS v3 3.1
EPSS 0.0046
EPSS Percentile 36.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (1)
sipwise/next_generation_communication_platform < mr11.5.1
Published Apr 10, 2024
Tracked Since Feb 18, 2026