CVE-2024-49705
- EPSS 0.12%
- Veröffentlicht 14.04.2025 12:15:15
- Zuletzt bearbeitet 28.10.2025 17:11:06
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to client-side Denial of Servise (DoS) attacks. An attacker might trick a user into using an URL with a d parameter set to an unhandled value. All the subsequent requests will not...
CVE-2024-49706
- EPSS 0.16%
- Veröffentlicht 14.04.2025 12:15:15
- Zuletzt bearbeitet 28.10.2025 17:10:03
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Open Redirect attacks by including base64 encoded URLs in the target parameter sent in a POST request to one of the endpoints. This vulnerability has been patched in version 79...
CVE-2024-49707
- EPSS 0.17%
- Veröffentlicht 14.04.2025 12:15:15
- Zuletzt bearbeitet 28.10.2025 17:09:12
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for resetting user's password with a malicious script, what causes the...
CVE-2024-49708
- EPSS 0.13%
- Veröffentlicht 14.04.2025 12:15:15
- Zuletzt bearbeitet 28.10.2025 17:08:15
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for setting delivery address with a malicious script, what causes the scr...
CVE-2024-49709
- EPSS 0.15%
- Veröffentlicht 14.04.2025 12:15:15
- Zuletzt bearbeitet 28.10.2025 17:07:50
Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session cookie value. An attacker with an access to user's browser might set such a cookie, wait until the user logs in and then use the same cookie to take over...
CVE-2024-10088
- EPSS 0.17%
- Veröffentlicht 14.04.2025 12:15:14
- Zuletzt bearbeitet 28.10.2025 17:12:28
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a login form with a malicious script, what causes the script to run in user's context....
CVE-2024-10089
- EPSS 0.13%
- Veröffentlicht 14.04.2025 12:15:14
- Zuletzt bearbeitet 28.10.2025 17:12:14
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Stored XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for changing user's data with a malicious script, what causes the script ...
CVE-2024-10090
- EPSS 0.17%
- Veröffentlicht 14.04.2025 12:15:14
- Zuletzt bearbeitet 28.10.2025 17:11:58
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might trick a user into filling a form designed for adding users with a malicious script, what causes the script to ru...
CVE-2024-13598
- EPSS 0.17%
- Veröffentlicht 14.04.2025 12:15:14
- Zuletzt bearbeitet 28.10.2025 17:11:46
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. Using a functionality of creating new form fields one creates new parameters vulnerable to XSS attacks. A user tricked into filli...
CVE-2024-10087
- EPSS 0.13%
- Veröffentlicht 14.04.2025 12:15:13
- Zuletzt bearbeitet 28.10.2025 16:52:58
Internet Starter, one of SoftCOM iKSORIS system modules, is vulnerable to Reflected XSS (Cross-site Scripting) attacks. An attacker might craft a link containing a malicious script, which then gets directly embedded in references to other resources, ...