U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2024-52875

Change History

CVE Modified by CVE 1/31/2025 3:15:07 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
http://seclists.org/fulldisclosure/2024/Dec/15

New CVE Received from MITRE 1/31/2025 3:15:07 AM

Action Type Old Value New Value
Added Description

								
							
							
						
An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertException.cs and /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is not properly sanitized before being used to generate a Location HTTP header in a 302 HTTP response. This can be exploited to perform Open Redirect or HTTP Response Splitting attacks, which in turn lead to Reflected Cross-Site Scripting (XSS). Remote command execution can be achieved by leveraging the upgrade feature in the admin interface.
Added CVSS V3.1

								
							
							
						
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-113
Added Reference

								
							
							
						
https://karmainsecurity.com/hacking-kerio-control-via-cve-2024-52875