logo

Vulnerabilities in SoftCOM iKSORIS software

ID: 9dbe45f7-d6b3-5209-99fe-29b39a3bce57

STIX ID: report--9dbe45f7-d6b3-5209-99fe-29b39a3bce57

Feed Name: CERT Polska

Threat Score
60/100

Date Published: 2025-04-14

Date Updated: 2026-04-19

Author: CERT Polska

...
...

CERT Polska disclosed a coordinated set of vulnerabilities in the Internet Starter module of SoftCOM iKSORIS (multiple CVEs), including several reflected and stored XSS flaws, an open redirect, an uncaught-exception client-side DoS, and session-fixation/arbitrary-session-cookie weaknesses that could enable account takeover; all issues were reported by Paweł Zdunek (Afine Team) and patched in iKSORIS version 79.0.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.