Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ksenia Security Lares 4.0 version 1.6 contains a URL redirection vulnerability in the 'cmdOk.xml' script that allows attackers to manipulate the 'redirectPage' GET parameter. Attackers can craft malicious links that redirect authenticated users to arbitrary websites when clicking on a specially constructed link hosted on a trusted domain. | |
| Title | Ksenia Security Lares 4.0 Home Automation 1.6 URL Redirection Vulnerability | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-30T22:41:46.247Z
Reserved: 2025-12-27T01:46:41.722Z
Link: CVE-2025-15112
No data.
Status : Received
Published: 2025-12-30T23:15:49.733
Modified: 2025-12-30T23:15:49.733
Link: CVE-2025-15112
No data.
OpenCVE Enrichment
No data.